Menu

Post image 1
Post image 2
1 / 2
0

JDownloader site hacked to replace installers with Python RAT malware

DEV Community·Mark0·23 days ago
#s336wF6q
Reading 0:00
15s threshold

The official website for JDownloader was recently compromised in a supply chain attack between May 6 and May 7, 2026. Attackers exploited an unpatched vulnerability in the site's content management system (CMS) to redirect "Download Alternative Installer" links for Windows and Linux shell installers to malicious third-party payloads. The developers confirmed the breach and took the site offline after users noticed that installers were being flagged by Microsoft Defender and were signed by suspicious entities like "Zipline LLC." Technical analysis reveals that the malicious Windows installer deploys a heavily obfuscated Python-based Remote Access Trojan (RAT) that acts as a modular bot framework. On Linux systems, the compromised script downloads ELF binaries, establishes persistence via systemd scripts, and utilizes SUID-root binaries to gain elevated privileges while masquerading as legitimate system processes.…

Continue reading — create a free account

Join HashtagPLUS to read full articles, follow hashtags, vote, and join the conversation.

Read More