The JDownloader Installer Supply Chain Attack
Updated 5 Oct 2026 · Incident date 6 May 2026 · vendor binary
JDownloader "Alternative Installer" for Windows and the Linux shell installer, served from the official site 6-7 May 2026the "Download Alternative Installer" Windows executable...On 6 and 7 May 2026, the official JDownloader website served malicious installers. The affected downloads were the Windows "Alternative Installer" and the Linux shell installer.
Attackers used an unpatched CMS flaw to change the download links. They did not change the real installer files. Anyone who ran one of these installers in that window must treat the machine as infected.
What happened
Attackers changed the download links on the JDownloader website for about one day. Gen Digital reports that the site was compromised on 6 May 2026, the window closed on 7 May, and clean downloads returned by 9 May. Security Affairs reports that the attackers used an unpatched CMS vulnerability and did not gain access to the underlying servers.
Gen Digital describes a multi-stage infection:
- The first-stage Windows installer was unsigned. Windows SmartScreen blocked it, and a user had to bypass the warning.
- A second-stage dropper unpacked five components from XOR-encrypted resources.
- The components included a Python remote access bot, an r77 rootkit stager with an AMSI bypass, and a Windows Defender Application Control policy. The policy blocks more than 50 security tools, including Avast, AVG, Avira, Windows Defender, HitmanPro and Kaspersky Virus Removal Tool.
- The bot found its command servers through pages on public paste sites, with a Tor address and a domain generation algorithm as fallbacks.
The Linux path used a separate payload. It installed a SUID binary and a shell profile script.
Vigilance reports the vendor binary that changed. Here the installer you trusted gained new behavior, and the scan block below shows what changed.
Affected versions
- Windows: the "Download Alternative Installer" links on the official site, 6 to 7 May 2026.
- Linux: the shell installer link, same window.
Gen Digital and Security Affairs report that these were not affected: in-app updates, macOS downloads, the Flatpak, Winget and Snap packages, and the main JAR package.
Indicators of compromise
- Stage 1 Windows installer SHA-256:
5a6636ce490789d7f26aaa86e50bd65c7330f8e6a7c32418740c1d009fb12ef3 - Stage 2 dropper SHA-256:
77a60b5c443f011dc67ace877f5b2ad7773501f3d82481db7f4a5238cf895f80 - Linux payload SHA-256:
6550672cac21e036882921dd934ee06552dc74d3b0a9e1ddc26f952855e11371 - Command servers:
parkspringshotel[.]comandauraguest[.]lk. Staging server:checkinnhotels[.]com. - Windows registry:
HKCU\SOFTWARE\Python\*,HKLM\SOFTWARE\$77stager,$77dll32,$77dll64,$77svc. - Windows mutex:
Global\0C3C1D37. Policy file:%WINDIR%\System32\CodeIntegrity\SIPolicy.p7b. - Linux:
/usr/bin/systemd-exec(SUID) and/etc/profile.d/systemd.sh. - Publisher names seen on the fake files: "Zipline LLC" and "The Water Team". The real installers carry an "AppWork GmbH" signature.
How to check
Check the signature and hash of the installer you ran. The real installer has an AppWork GmbH signature. On Linux, test for the persistence files.
ls -l /usr/bin/systemd-exec /etc/profile.d/systemd.sh
On Windows, check for the policy file and compare the installer hash with the list above.
Get-FileHash .\JDownloader2Setup.exe -Algorithm SHA256; Test-Path "$env:WINDIR\System32\CodeIntegrity\SIPolicy.p7b"
Replace the file name with the name of the file you downloaded. A policy file that you did not create is a sign of infection.
What to do now
- Find out if anyone downloaded the Windows Alternative Installer or the Linux shell installer on 6 or 7 May 2026.
- If a machine ran one, reinstall the operating system. Gen Digital states that a clean reinstall is the safest fix, because the rootkit makes partial cleanup unreliable.
- Do not sign in to sensitive accounts from that machine until it is rebuilt. Change those passwords from a clean device.
- Block the command domains above.
- Delete an unexpected
SIPolicy.p7bfile and reboot only if you cannot rebuild at once. Gen Digital lists this as a step for a user-created policy.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 35 (1 Added) HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. NEW FILE JDownloader.exe It runs a command on its own when it is installed, downloads from the internet and restarts itself after a reboot.
Frequently asked questions
Was the official JDownloader website compromised?
Yes. On 6 and 7 May 2026 attackers used an unpatched CMS flaw to swap the download links for the Windows Alternative Installer and the Linux shell installer. Clean links returned by 9 May.
How can I tell if my JDownloader installer was malicious?
Check the file signature. Real installers carry an AppWork GmbH signature. The malicious Windows files were unsigned or showed other publisher names. You can also compare the SHA-256 hash with the indicator list.
Sources
More supply chain attacks
- CPUID CPU-Z / HWMonitor download compromise 9 Apr 2026
- DAEMON Tools trojanized installers 8 Apr 2026
- eScan antivirus update server compromise (2026) 20 Jan 2026
- QuickFox VPN trojanized Windows installer 1 Aug 2025
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.