Briefing

JDownloader site hacked to replace installers with Python RAT malware

security
by Lawrence Abrams ·

Reinstall OS and reset passwords on any machine that ran the compromised JDownloader installers.

What to do now

Reinstall OS and reset passwords on any machine that ran the compromised JDownloader installers.

Summary

The official JDownloader website was compromised on May 6‑7, 2026, causing the Windows “Download Alternative Installer” and Linux shell installer links to point to malicious third‑party payloads. Attackers exploited an unpatched CMS vulnerability that allowed them to modify website content without gaining server‑level access, leaving the main JDownloader JAR, macOS, Flatpak, Winget, Snap packages and in‑app updates untouched. The malicious Windows installer is a Python‑based RAT loader that deploys an obfuscated Python framework, while the Linux installer injects a script that downloads ELF binaries, installs a SUID‑root systemd‑exec binary, creates a persistence script in /etc/profile.d/systemd.sh and masquerades as /usr/libexec/upowerd.

Users who downloaded and executed the affected installers are advised to reinstall their operating systems and reset all passwords, as the malware could have exfiltrated credentials. The malicious Windows payload fetches a PowerShell batch file that performs privilege escalation and installs the final Rust‑based infostealer. The Linux payload extracts two ELF binaries named pkg and systemd‑exec, copies the main payload to /root/.local/share/.pkg, and launches the malware while masquerading as a legitimate system daemon. JDownloader’s developers confirmed that the compromise affected only the alternative installer links and that the site was taken offline for investigation. The incident highlights the growing trend of attackers targeting software download sites to distribute malware to unsuspecting users.

Key changes

  • JDownloader website compromised, download links redirected to malicious payloads
  • Windows installer replaced with Python RAT loader
  • Linux installer modified to download ELF binaries and install SUID‑root systemd‑exec
  • Attack limited to alternative Windows and Linux installers; main JDownloader JAR and macOS downloads untouched
  • Users can verify legitimacy via Digital Signatures tab
  • Malicious Windows payload is a modular Python RAT
  • Malicious Linux installer installs persistence script in /etc/profile.d/systemd.sh
  • Users advised to reinstall OS and reset passwords

Affects

none

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting