---
title: "JDownloader site hacked to replace installers with Python RAT malware"
url: https://daily.dev/posts/jdownloader-site-hacked-to-replace-installers-with-python-rat-malware-zf16t1da8
source_url: https://www.bleepingcomputer.com/news/security/jdownloader-site-hacked-to-replace-installers-with-python-rat-malware
type: article
source: "BleepingComputer"
published: 2026-05-09T19:30:32.261Z
updated: 2026-05-09T21:58:10.515Z
tags: ["cyber", "python", "malware"]
reading_time: 5
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# JDownloader site hacked to replace installers with Python RAT malware

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 5 min read · 0 upvotes · 0 comments

## Summary

The JDownloader download manager website was compromised between May 6–7, 2026, with attackers exploiting an unpatched CMS vulnerability to replace Windows and Linux installer download links with malicious payloads. The Windows payload deploys a heavily obfuscated Python-based remote access trojan (RAT) acting as a modular bot framework communicating with C2 servers. The Linux installer was injected with code that downloads ELF binaries, installs a SUID-root binary, and establishes persistence via systemd masquerading. In-app updates, macOS, Flatpak, Winget, Snap, and the main JAR were unaffected. Users who installed the compromised versions are advised to reinstall their OS and reset all credentials. This is part of a broader trend of supply chain attacks targeting popular software download sites.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/jdownloader-site-hacked-to-replace-installers-with-python-rat-malware>

## Similar posts on daily.dev

- [Russian hackers trojanize WebEx, Zoom apps to push Starland malware](https://daily.dev/posts/russian-hackers-trojanize-webex-zoom-apps-to-push-starland-malware-kv7oahrsr) · BleepingComputer · 0 upvotes · 0 comments
- [Fake Roblox Xeno script launcher pushes infostealer, RAT malware](https://daily.dev/posts/fake-roblox-xeno-script-launcher-pushes-infostealer-rat-malware-qtwjss6dl) · BleepingComputer · 0 upvotes · 0 comments
- [Fake OSINT and GPT Utility GitHub Repos Spread PyStoreRAT Malware Payloads](https://daily.dev/posts/fake-osint-and-gpt-utility-github-repos-spread-pystorerat-malware-payloads-9jtaz4clq) · The Hacker News · 0 upvotes · 0 comments

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#python](https://daily.dev/tags/python), [#malware](https://daily.dev/tags/malware)

[View this post on daily.dev](https://daily.dev/posts/jdownloader-site-hacked-to-replace-installers-with-python-rat-malware-zf16t1da8)
