ctipilot.ch

JDownloader official site compromised

incident · incident:jdownloader-supply-chain-2026

JDownloader official site compromised — Windows/Linux installers swapped for Python RAT (~48 h window)

Coverage timeline
2
first 2026-05-04 → last 2026-05-10
Peak priority
notable
2 notable
Sources cited
5
3 hosts
Sections touched
2
active-threats, weekly-incidents-recap
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
6
pinned v19.1 · see below
2026-05-042 appearances2026-05-10

ATT&CK techniques

6 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1195Supply Chain Compromise×1

Adversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise.

Evidence: 2026-05-10/jdownloader-official-site-compromised-windows-and-linux-inst · ATT&CK page ↗

T1195.002Supply Chain Compromise: Compromise Software Supply Chain×1

Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.

Evidence: 2026-05-10/jdownloader-official-site-compromised-windows-and-linux-inst · ATT&CK page ↗

Execution TA0002

T1059Command and Scripting Interpreter×1

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.

Evidence: 2026-05-10/jdownloader-official-site-compromised-windows-and-linux-inst · ATT&CK page ↗

T1059.006Command and Scripting Interpreter: Python×1

Adversaries may abuse Python commands and scripts for execution. Python is a very popular scripting/programming language, with capabilities to perform many functions. Python can be executed interactively from the command-line (via the <code>python.exe</code> interpreter) or via scripts (.py) that can be written and distributed to different systems. Python code can also be compiled into binary executables.

Evidence: 2026-05-10/jdownloader-official-site-compromised-windows-and-linux-inst · ATT&CK page ↗

Stealth TA0005

T1036Masquerading×1

Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools. Masquerading occurs when the name or location of an object, legitimate or malicious, is manipulated or abused for the sake of evading defenses and observation. This may include manipulating file metadata, tricking users into misidentifying the file type, and giving legitimate task or service names.

Evidence: 2026-05-10/jdownloader-official-site-compromised-windows-and-linux-inst · ATT&CK page ↗

T1036.005Masquerading: Match Legitimate Resource Name or Location×1

Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation.

Evidence: 2026-05-10/jdownloader-official-site-compromised-windows-and-linux-inst · ATT&CK page ↗

Story timeline

  1. 2026-05-10JDownloader official site compromised — Windows and Linux installers swapped for a Python RAT for ~48 hours
    active-threats
  2. 2026-05-04JDownloader official site compromised — Windows and Linux installers swapped for ~48 hours
    weekly-incidents-recap

Where this entity is cited

  • weekly-incidents-recap1
  • active-threats1

Source distribution

  • attack.mitre.org3 (60%)
  • cyberkendra.com1 (20%)
  • piunikaweb.com1 (20%)

explore in graph

Entries about JDownloader official site compromised (2)

2026-05-10 · view entry permalink →

NOTABLE

JDownloader official site compromised — Windows and Linux installers swapped for a Python RAT for ~48 hours

The official download page of JDownloader, a German-developed (AppWork GmbH) Java-based download manager popular across European user bases, was compromised between approximately 2026-05-06 and 2026-05-08; attackers replaced the Windows and Linux installers with malicious counterparts (PiunikaWeb, 2026-05-08 · CyberKendra, 2026-05-07). The intrusion exploited an unpatched access-control flaw in the site's content-management layer, allowing unauthenticated modification of download-link targets without altering the main JAR, the in-app updater, the macOS bundle, or the package-manager distributions (Winget, Flatpak, Snap). Trojanised Windows executables bore forged publisher names — "Zipline LLC", "The Water Team", "Peace Team" — instead of the legitimate AppWork GmbH signature, triggering Windows SmartScreen warnings that helped some users detect the substitution before execution. The substituted installers are described in available reporting as carrying a Python-based remote-access payload; the precise capability description has not been corroborated by a named research lab in this run's window (. The JDownloader team confirmed the breach and have asked users to verify file hashes against the project's published SHA-256 manifest.

ATT&CK mapping: T1195.002 Supply Chain Compromise: Software Supply Chain, T1036.005 Match Legitimate Name (forged AppWork-adjacent publisher names), T1059.006 Python for the RAT runtime.

threat10 May 05:00Zmulti-sourceOpen finding ↗

2026-05-04 · view entry permalink →

NOTABLE

JDownloader official site compromised — Windows and Linux installers swapped for ~48 hours

The official download page of JDownloader (German-developed AppWork GmbH, Java-based download manager popular across European user bases) was compromised between approximately 2026-05-06 and 2026-05-08; attackers exploited an unpatched access-control flaw in the site's CMS layer to replace Windows and Linux installer download links without altering the main JAR, the in-app updater, the macOS bundle, or the package-manager distributions (Winget, Flatpak, Snap). Trojanised Windows executables bore forged publisher names — "Zipline LLC", "The Water Team", "Peace Team" — triggering Windows SmartScreen warnings that helped some users detect the substitution. The substituted installers carry a Python-based remote-access payload; a more specific capability description has not been corroborated by a named research lab in available reporting. The JDownloader team confirmed and asked users to verify file hashes against the project's published SHA-256 manifest (PiunikaWeb, 2026-05-08 · CyberKendra, 2026-05-07 · daily 2026-05-10).

incident04 May 05:00Zmulti-sourceOpen finding ↗