The JDownloader Installer Supply Chain Attack

Updated 5 Oct 2026 · Incident date 6 May 2026 · vendor binary

PackageJDownloader "Alternative Installer" for Windows and the Linux shell installer, served from the official site 6-7 May 2026
Filethe "Download Alternative Installer" Windows executable...

On 6 and 7 May 2026, the official JDownloader website served malicious installers. The affected downloads were the Windows "Alternative Installer" and the Linux shell installer.

Attackers used an unpatched CMS flaw to change the download links. They did not change the real installer files. Anyone who ran one of these installers in that window must treat the machine as infected.

What happened

Attackers changed the download links on the JDownloader website for about one day. Gen Digital reports that the site was compromised on 6 May 2026, the window closed on 7 May, and clean downloads returned by 9 May. Security Affairs reports that the attackers used an unpatched CMS vulnerability and did not gain access to the underlying servers.

Gen Digital describes a multi-stage infection:

The Linux path used a separate payload. It installed a SUID binary and a shell profile script.

Vigilance reports the vendor binary that changed. Here the installer you trusted gained new behavior, and the scan block below shows what changed.

Affected versions

Gen Digital and Security Affairs report that these were not affected: in-app updates, macOS downloads, the Flatpak, Winget and Snap packages, and the main JAR package.

Indicators of compromise

How to check

Check the signature and hash of the installer you ran. The real installer has an AppWork GmbH signature. On Linux, test for the persistence files.

ls -l /usr/bin/systemd-exec /etc/profile.d/systemd.sh

On Windows, check for the policy file and compare the installer hash with the list above.

Get-FileHash .\JDownloader2Setup.exe -Algorithm SHA256; Test-Path "$env:WINDIR\System32\CodeIntegrity\SIPolicy.p7b"

Replace the file name with the name of the file you downloaded. A policy file that you did not create is a sign of infection.

What to do now

  1. Find out if anyone downloaded the Windows Alternative Installer or the Linux shell installer on 6 or 7 May 2026.
  2. If a machine ran one, reinstall the operating system. Gen Digital states that a clean reinstall is the safest fix, because the rootkit makes partial cleanup unreliable.
  3. Do not sign in to sensitive accounts from that machine until it is rebuilt. Change those passwords from a clean device.
  4. Block the command domains above.
  5. Delete an unexpected SIPolicy.p7b file and reboot only if you cannot rebuild at once. Gen Digital lists this as a step for a user-created policy.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old JDownloader-prev --new JDownloader-current
files scanned: 35 (1 Added)

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

NEW FILE   JDownloader.exe
           It runs a command on its own when it is installed, downloads from the internet and restarts itself after a reboot.

Frequently asked questions

Was the official JDownloader website compromised?

Yes. On 6 and 7 May 2026 attackers used an unpatched CMS flaw to swap the download links for the Windows Alternative Installer and the Linux shell installer. Clean links returned by 9 May.

How can I tell if my JDownloader installer was malicious?

Check the file signature. Real installers carry an AppWork GmbH signature. The malicious Windows files were unsigned or showed other publisher names. You can also compare the SHA-256 hash with the indicator list.

Sources

  1. gendigital.com/blog/insights/research/inside-the-jdownloader-supply-chain-attack
  2. securityaffairs.com/191920/malware/official-jdownloader-site-served-malware-to-windows-and-linux-users.html

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free