PULSE NAME
Website installer incident (May 2026)
WHITE AlienVault 2026-05-11 Modified: 2026-05-11
14
IOCs
MEDIUM VOLUME
In early May 2026, attackers compromised the official JDownloader website by manipulating specific installer download links through the content management system. Between May 6-7, 2026 (UTC), users who downloaded Windows installers via "Download Alternative Installer" links or the Linux shell installer were redirected to malicious third-party files instead of genuine installers. The attackers gained CMS-level access only, not server or filesystem control. The incident was detected on May 7 via Reddit alerts, and the server was immediately taken offline. Malicious links were removed, legitimate links restored, and security hardened before the site resumed normal operations on May 8-9. In-app updates and other download paths remained unaffected. Users who executed downloaded installers during the risk window are advised to perform clean OS reinstalls and change passwords from trusted devices.
Indicators of Compromise (8 / 14 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 04cb9f0bca6e0e4ed30bc92726590724bf60938440b3825252657d1b3af45495 2026-05-11
FileHash-SHA256 32891c0080442bf0a0c5658ada2c3845435b4e09b114599a516248723aad7805 2026-05-11
FileHash-SHA256 4ff7eec9e69b6008b77de1b6e5c0d18aa717f625458d80da610cb170c784e97c 2026-05-11
FileHash-SHA256 5a6636ce490789d7f26aaa86e50bd65c7330f8e6a7c32418740c1d009fb12ef3 2026-05-11
FileHash-SHA256 6d975c05ef7a164707fa359284a31bfe0b1681fe0319819cb9e2c4eec2a1a8af 2026-05-11
FileHash-SHA256 de8b2bdfc61d63585329b8cfca2a012476b46387435410b995aeae5b502bd95e 2026-05-11
FileHash-SHA256 e4a20f746b7dd19b8d9601b884e67c8166ea9676b917adea6833b695ba13de16 2026-05-11
FileHash-SHA256 fb1e3fe4d18927ff82cffb3f82a0b4ffb7280c85db5a8a8b6f6a1ac30a7e7ed9 2026-05-11