Skip to content

// #download-hijacking

1 article

💻 AppSec

JDownloader Official Download Site Hijacked to Serve Python RAT in Supply Chain Attack

The official JDownloader download site was compromised during a window of approximately 18 hours between 6 and 7 May 2026, with legitimate installer downloads replaced by a trojanised package delivering a Python-based remote access trojan. JDownloader is a popular open-source download manager with millions of users. Users who installed JDownloader during the compromise window should treat their system as compromised and perform immediate credential rotation and system remediation.

#supply-chain +6