{"id":659949,"date":"2026-05-10T09:55:12","date_gmt":"2026-05-10T09:55:12","guid":{"rendered":"https:\/\/www.newsbeep.com\/ca\/659949\/"},"modified":"2026-05-10T09:55:12","modified_gmt":"2026-05-10T09:55:12","slug":"jdownloader-site-hacked-to-replace-installers-with-python-rat-malware","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ca\/659949\/","title":{"rendered":"JDownloader site hacked to replace installers with Python RAT malware"},"content":{"rendered":"<p style=\"text-align:center\"><img loading=\"lazy\" decoding=\"async\" alt=\"JDownloader\" height=\"900\" src=\"https:\/\/www.newsbeep.com\/ca\/wp-content\/uploads\/2026\/05\/jdownloader-header.jpg\" width=\"1600\"\/><\/p>\n<p>The website for the popular JDownloader download manager was compromised earlier this week to distribute malicious Windows and Linux installers, with the Windows payload found deploying\u00a0a Python-based remote access trojan.<\/p>\n<p>The supply chain attack affects those who downloaded installers from the official website between May 6 and May 7, 2026 via the Windows &#8220;Download Alternative Installer&#8221; links or the Linux shell installer.<\/p>\n<p>According to the developers, the attackers modified the website&#8217;s download links to point to malicious third-party payloads rather than legitimate installers.<\/p>\n<p>JDownloader is a widely used free download management application that supports automated downloads from file-hosting services, video sites, and premium link generators. The software has been available for more than a decade and is used by millions worldwide across Windows, Linux, and macOS.<\/p>\n<p>The JDownloader supply chain attack<\/p>\n<p>The compromise was first reported on <a href=\"https:\/\/old.reddit.com\/r\/jdownloader\/comments\/1t6goqe\/is_the_website_hacked\/\" target=\"_blank\" rel=\"nofollow noopener\">Reddit<\/a> by a user named &#8220;PrinceOfNightSky,&#8221; who noticed that downloaded installers were being flagged by Microsoft Defender.<\/p>\n<p>&#8220;I been using Jdownloader and switched to a new PC a few weeks ago. Luckily I had the installer in a usb drive but decided to download the latest version,&#8221; posted PrinceOfNightSky to Reddit.<\/p>\n<p>&#8220;The website is official but all the Exes for windows are being reported as malicious software by windows and the developer is being listed as &#8216;Zipline LLC.&#8217; And other times it&#8217;s saying &#8216;The Water Team&#8217; The software is obviously by Appwork and I have to manually unblock it from windows to run it which I will not do.&#8221;<\/p>\n<p>The JDownloader developers <a href=\"https:\/\/old.reddit.com\/r\/jdownloader\/comments\/1t6goqe\/is_the_website_hacked\/okhg2ur\/\" target=\"_blank\" rel=\"nofollow noopener\">later confirmed<\/a> that the site had been compromised and took the website offline to investigate the incident.<\/p>\n<p>In an <a href=\"https:\/\/jdownloader.org\/incident_8.5.2026.html?v=20260508277000\" target=\"_blank\" rel=\"nofollow noopener\">incident report<\/a>, the devs\u00a0said their website was compromised by\u00a0attackers exploiting an unpatched vulnerability that allowed them to change website access control lists and content without authentication.<\/p>\n<p>&#8220;Changes were made through the website&#8217;s content management system, affecting published pages and links,&#8221; reads the incident report.<\/p>\n<p>&#8220;The attacker did not gain access to the underlying server stack \u2014 in particular no access to the host filesystem or broader operating-system-level control beyond CMS-managed web content.&#8221;<\/p>\n<p>The developers stated that the compromise affected only the alternative Windows installer download links and the Linux shell installer link.\u00a0In-app updates, macOS downloads, Flatpak, Winget, Snap packages, and the main JDownloader JAR package were not modified.<\/p>\n<p>The developers also said that users can confirm if an installer is legitimate by right-clicking the file, selecting Properties, and then clicking the Digital Signatures tab.<\/p>\n<p>If Digital Signatures shows it was signed by\u00a0&#8220;AppWork GmbH,&#8221; then it is legitimate. However, if the file is not signed or is by a different name, it should be avoided.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"Signed legitimate JDownloader installer\" height=\"500\" src=\"https:\/\/www.newsbeep.com\/ca\/wp-content\/uploads\/2026\/05\/jdownloader-signed.jpg\" width=\"398\"\/>Signed legitimate JDownloader installer<br \/>Source: BleepingComputer<\/p>\n<p>The JDownloader team said that analyzing the malicious payloads was &#8220;out of our scope,&#8221; but shared an archive of the malicious installers so that others could analyze them.<\/p>\n<p>Cybersecurity researcher <a href=\"https:\/\/x.com\/thomasklemenc\/status\/2052715025450598904\" target=\"_blank\" rel=\"nofollow noopener\">Thomas Klemenc<\/a> analyzed the malicious Windows executables and shared indicators of compromise (IOCs) for the malware.<\/p>\n<p>According to Klemenc, the malware acts as a\u00a0loader that deploys a heavily obfuscated Python-based RAT.\u00a0<\/p>\n<p>Klemenc said the Python payload acts as a modular bot and RAT framework, allowing attackers to execute Python code delivered from the command and control (C2) servers.<\/p>\n<p>The researcher also shared two command and control servers used by the malware:<\/p>\n<p>&#13;<br \/>\nhttps:\/\/parkspringshotel[.]com\/m\/Lu6aeloo.php&#13;<br \/>\nhttps:\/\/auraguest[.]lk\/m\/douV2quu.php<\/p>\n<p>BleepingComputer&#8217;s analysis of the modified Linux shell installer found malicious code injected into the script that downloads an archive from &#8216;checkinnhotels[.]com&#8217; disguised as an SVG file.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"Malicious code in modified JDownloader Linux installer\" height=\"600\" src=\"https:\/\/www.newsbeep.com\/ca\/wp-content\/uploads\/2026\/05\/malicious-code-in-jdownloader-linux-installer.jpg\" width=\"1341\"\/>Malicious code in the modified JDownloader Linux installer<br \/>Source: BleepingComputer<\/p>\n<p>Once downloaded, the script extracts two ELF binaries named &#8216;pkg` and `systemd-exec` and then installs &#8216;systemd-exec&#8217;\u00a0as a SUID-root binary in &#8216;\/usr\/bin\/&#8217;.<\/p>\n<p>The installer then copied the main payload to &#8216;\/root\/.local\/share\/.pkg&#8217;, created a persistence script in &#8216;\/etc\/profile.d\/systemd.sh&#8217;, and launched the malware while masquerading as &#8216;\/usr\/libexec\/upowerd`.<\/p>\n<p>The &#8216;pkg&#8217; payload is also heavily obfuscated using Pyarmor, so it is unclear what functionality it performs.<\/p>\n<p>JDownloader says users are only at risk if they downloaded and executed the affected installers while the site was compromised.<\/p>\n<p>As arbitrary code could have been executed by the malware on infected devices, those who installed the malicious installers are advised to reinstall their operating systems.<\/p>\n<p>It is also possible that credentials were compromised on devices, so it is strongly advised to reset passwords after cleaning the devices.<\/p>\n<p>Hackers have increasingly targeted the websites of popular software tools this year to distribute malware to unsuspecting users.<\/p>\n<p>In April,\u00a0hackers <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/supply-chain-attack-at-cpuid-pushes-malware-with-cpu-z-hwmonitor\/\" target=\"_blank\" rel=\"nofollow noopener\">compromised the CPUID website<\/a>\u00a0to change download links that served malicious executables for the popular CPU-Z and HWMonitor tools.<\/p>\n<p>Earlier this month, threat actors <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/daemon-tools-trojanized-in-supply-chain-attack-to-deploy-backdoor\/\" target=\"_blank\" rel=\"nofollow noopener\">compromised the DAEMONTOOLS website<\/a> to distribute trojanized installers containing a backdoor.<\/p>\n<p>        <a href=\"https:\/\/hubs.li\/Q04crVgD0\" target=\"_blank\" rel=\"noopener nofollow\"><br \/>\n            <img decoding=\"async\" alt=\"article image\" src=\"https:\/\/www.newsbeep.com\/ca\/wp-content\/uploads\/2026\/05\/autonomous-validation2.jpg\" class=\"b-lazy\"\/><\/a><\/p>\n<p>AI chained four zero-days into one exploit that bypassed both renderer and OS sandboxes. A wave of new exploits is coming.<\/p>\n<p>At the Autonomous Validation Summit (May 12 &amp; 14), see how autonomous, context-rich validation finds what&#8217;s exploitable, proves controls hold, and closes the remediation loop.<\/p>\n<p>        <a class=\"article-link\" href=\"https:\/\/hubs.li\/Q04crVgD0\" target=\"_blank\" rel=\"noopener nofollow\">Claim Your Spot<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"The website for the popular JDownloader download manager was compromised earlier this week to distribute malicious Windows and&hellip;\n","protected":false},"author":2,"featured_media":659950,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[49,48,61],"class_list":["post-659949","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-ca","tag-canada","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/659949","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/comments?post=659949"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/659949\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media\/659950"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media?parent=659949"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/categories?post=659949"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/tags?post=659949"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}