Proprietary · · 1 day

JDownloader CMS served trojanized installer

Attackers exploited a CMS vulnerability on the JDownloader website to swap download links for Windows and Linux installers with trojanized binaries containing a Remote Access Trojan (RAT). The real installers and RSA-signed in-app updater were not modified.

The popular open-source download manager JDownloader briefly served malicious installers from its own website in early May 2026, after attackers exploited an unpatched vulnerability in the project's content management system to swap selected download links to trojanized third-party files. The project's signed installers and in-app updater were not modified.

In a public incident notice, the JDownloader team described the event as a website-content compromise, not a build compromise. Attackers used the jdownloader.org CMS to change selected download links, so users who chose the Windows "Download Alternative Installer" path or the Linux shell installer could end up with unrelated malicious files instead. The vendor said genuine installer packages were not modified, the underlying host filesystem was not reached, and personal data was not accessed. The in-app updater was outside the affected path and continued to verify updates with RSA signatures.

The risk window ran from shortly after midnight UTC on May 6 through May 7, 2026. The compromise went undetected for more than a day until a Reddit user spotted unexpected Windows SmartScreen warnings and the malware attempting to disable Microsoft Defender. According to the project's writeup, the team was alerted at 17:06 UTC on May 7, took the site down 18 minutes later, removed the malicious link targets, restored legitimate links, and kept the site offline until further verification was complete. Researchers later identified the payload as a multi-component framework combining a Python remote access trojan protected by PyArmor, an r77 rootkit stager, and a Windows Defender Application Control policy designed to disable numerous antivirus products.

The most useful evidence for defenders is the substituted artifact set itself. JDownloader published exact byte sizes and SHA-256 hashes for one Linux shell installer substitute and seven Windows executable substitutes. Those hashes identify the malicious files, not JDownloader's clean release packages.

Appendix · Affected releases

JDownloader2Setup_unix_nojre.sh jdownloader website linux installer
  • Observed malicious substitute file size: 7,934,496 bytes. JDownloader stated the genuine installer packages were not modified; CMS-managed website links were redirected.
JDownloader2Setup_windows-amd64_v11_0_30.exe jdownloader website alternative installer
  • Observed malicious substitute file size: 104,910,336 bytes.
JDownloader2Setup_windows-amd64_v17_0_18.exe jdownloader website alternative installer
  • Observed malicious substitute file size: 101,420,032 bytes.
JDownloader2Setup_windows-amd64_v1_8_0_482.exe jdownloader website alternative installer
  • Observed malicious substitute file size: 61,749,248 bytes.
JDownloader2Setup_windows-amd64_v21_0_10.exe jdownloader website alternative installer
  • Observed malicious substitute file size: 107,124,736 bytes.
JDownloader2Setup_windows-x86_v11_0_29.exe jdownloader website alternative installer
  • Observed malicious substitute file size: 87,157,760 bytes.
JDownloader2Setup_windows-x86_v17_0_17.exe jdownloader website alternative installer
  • Observed malicious substitute file size: 86,576,128 bytes.
JDownloader2Setup_windows-x86_v1_8_0_472.exe jdownloader website alternative installer
  • Observed malicious substitute file size: 62,498,304 bytes.

References

  1. Website installer incident - May 2026jdownloader.org
  2. Sophos Endpoint in action - Blocking a novel supply chain attacksophos.com
  3. Inside the JDownloader Supply Chain Attackgendigital.com
  4. Reddit user spots SmartScreen warnings on JDownloader installerreddit.com

Source record: proprietary/jdownloader/meta.yaml