Attackers compromised JDownloader’s official website and replaced legitimate download links with malware-laced installers in a supply-chain-style attack. The breach was traced to an unpatched CMS vulnerability that allowed unauthenticated changes to access control lists, letting the attackers grant themselves edit rights and swap the official URLs. JDownloader said the malicious files were distributed through the Windows Alternative Installer and the Linux shell script on its alternative download page, while the main JDownloader.jar, macOS installers, Winget, Flatpak, Snap packages, and in-app updates were not affected because existing update mechanisms remained protected by RSA-signed verification.
The compromise was discovered after users reported suspicious behavior, including Windows SmartScreen warnings and an unexpected publisher name, in posts on Reddit. JDownloader took the server offline for emergency maintenance, patched and hardened the site, and later restored service. The developers warned that anyone who ran the affected installers during the exposure window on 6 and 7 May should treat the system as fully compromised and consider a complete operating system reinstall, noting that antivirus tools may not remove all persistence mechanisms and that some reports indicated the malware could disable Windows Defender.

Trace attribution and downstream blast radius.
6 events from the most recent confirmed update back to the earliest known activity.
JDownloader published indicators of compromise and technical details for the malware delivered through the trojanized installers, including hashes, C2 URLs, registry keys, process names, decryption keys, and fake publisher names. The disclosure also described the payload as a layered Python-based RAT using multiple encryption schemes, dead-drop resolvers, and pythonw.exe for persistence and execution.
JDownloader brought its website back online after patching the exploited vulnerability and hardening the server. The developers advised anyone who executed the affected installers during the compromise window to consider a full operating system reinstall.
After investigating user reports, the JDownloader team confirmed the website compromise and took the server offline for emergency maintenance. The developers began investigating the incident and warned affected users that antivirus scans alone might not remove all persistence mechanisms.
A Reddit user and other community members flagged SmartScreen warnings, a suspicious publisher name, and other abnormal installer behavior, helping surface the compromise. Some reports indicated the malware could disable Windows Defender.
On 6 and 7 May, users downloading the Windows Alternative Installer or Linux shell script from JDownloader’s site could receive malware-laced files. Other distribution channels, including the main JDownloader.jar file, macOS installers, Winget, Flatpak, Snap, and in-app updates, were reported as unaffected.
Attackers abused an unpatched CMS vulnerability that allowed unauthenticated modification of access control lists, giving them the ability to edit JDownloader website content and replace official download URLs with malicious ones. The compromise affected the alternative download page and targeted Windows and Linux installer downloads.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 26 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
9 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcecybersecuritynews.com
Open sourcemalwarebytes.com
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcegendigital.com
Open sourcehackread.com
Open sourcejdownloader.org
Open sourceneowin.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.