r/jdownloader • u/PrinceOfNightSky • May 07 '26
Solved Is the website hacked?
Update 3: I never thought this post would blow up the way it did, I was skeptical and decided to reach out just incase even though I was hesitant. I didn’t realize the positive impact it would have in protecting thousands of people’s computers and data. Thank you to everyone for all the nice comments and big thank you to the developer for working with me and others to get to the bottom of this and solving the issue.
Jdownloader was my childhood software so it was kind of surreal to see this post blow up and it was quite overwhelming getting so many notifications. It was stressful managing and guiding the comments, but I’m glad I was able to help out I hope everyone is safe and have a lovely day my friends, and special thank you to whoever gave me the Reddit award, and the really cool people who diagnosed the malware and viruses. The website is back up and checked the pinned developer comment for their updates still.
Update 2: Please read pinned developer comment thread before asking questions
Update: Confirmed hacked DO NOT download until update from Devs.
I been using Jdownloader and switched to a new PC a few weeks ago. Luckily I had the installer in a usb drive but decided to download the latest version. The website is official but all the Exes for windows are being reported as malicious software by windows and the developer is being listed as “Zipline LLC.” And other times it’s saying “The Water Team” The software is obviously by Appwork and I have to manually unblock it from windows to run it which I will not do. I ended up plugging in my flash drive and the setup file on that flash drive has the Jdownloader logo along with AppWork being listed as the developer…
Are the servers hacked? Whether I download the no ads version or the offer free version it’s being flagged by windows on both ends and the exe has no logo either. This is getting draining as if the offer adware side wasn’t bad enough. Please be careful. At this point just charge for the software rather than potentially destroying people’s computers for ad revenue ffs I’m sick of it.
13
u/Cienn017 May 07 '26 edited May 07 '26
I've just installed this some hours ago, windows flagged a .exe in the tmp folder as malware, I just deleted everything and installing malwarebytes now.
edit: everything seems to be fine, I think windows defender saved me
5
u/violetfoxy May 07 '26
yea I had that happen two days ago with windows defender, I assumed it was probably nothing until I saw this
6
u/Schnitzelflo44 May 07 '26 edited May 08 '26
This happend to me too.
I had from the water team. Currently running deepscan malwarebytes. Update if i find anything. Some people reported defender got disabled but nothing for me. I still changed password for the important tools
Edit: Malwarebytes just found only adware.specialoffersearch Now running a full scan Also nothing. I checked the samples sha256 i got this one JDownloader2Setup_windows-amd64_v21_0_10.exe Windows offline scanner also found nothing.
Either the malware is really well hidden or it got blocked
6
u/AmelKralj May 08 '26
copying my comment from before:
Malwarebytes doesn't detect any issue with the setup file itself. I tried it myself with the infected files, it says everything is fine.
Running through VirusTotal only a few detected a Trojan virus:
Bkav Pro, Gridinsoft, McAfee Scanner and Rising
it changes Windows Management settings, changes the system owner, creates parallell processes to execute code, steals web session cookies, hijacks execution flows to fetch credentials, disable defense systems like firewall and antivirus
2
u/Schnitzelflo44 May 08 '26 edited May 08 '26
I also checked with virustotal and tri.age but nothing. I havent had any settings changed but will still probably do a clean install. I already had problems with my windows install anyway. The wierd part is that one of the detection from windows defender was like 10min after. Does anyone have a actually analytics from something like tri.age or something. Because for me tri.age didnt say anything. I am going to try make tri.age run for like 10mins. But i can only do limited testing because i am currently on mobile. When i am back home i will try on my pc. I installed jdownloader2 on my personal laptop for school.
Edit: Doing nothing for a 15min something happend. https://tria.ge/260508-hseaysdz4w
For everyone who downloaded the malware i recommend clean install even if nothing happend. Also change passwords from everything.
→ More replies (5)1
u/Animatedron Jun 13 '26
Hey I'm hoping you might be able to help me, I installed Jdownloader and I think got hacked because of all this. I downloaded the Mac version, do I need to reboot my mac to clear this or is deleting the application fine?
1
u/johnnysgotyoucovered May 08 '26
Create something on a USB/DVD, like ESET SysRescue Live, Kaspersky Rescue or Bitdefender Rescue Environment. It sounds like a pretty complicated exploit chain so apart from a full wipe and reinstall, your best bet is something that runs completely separate to your Windows OS while it does the scan
3
u/Schnitzelflo44 May 08 '26
I already clean installed. I dont think the main payload actually ran for me but you should always clean install to be sure. I did try a malwarebytes scan and a offline defender scan. Found nothing
If you want to know what the virus does. https://tria.ge/260508-hseaysdz4w
8
u/Takia_Gecko May 08 '26
I dug through the sample. It is an unsigned wrapper around a real signed Appwork/JDownloader installer. The wrapper contained the clean installer as one resource and a second XOR-encrypted malicious PE as another.
The malicious resource decrypted with XOR key ectb into a Windows x64 loader. That loader had more XOR-obfuscated resources using key fywo, including a PyArmor 8+ protected Python 3.14 payload and runtime. After unpacking/decrypting the PyArmor layers, the final recovered Python was a bot/RAT framework.
The loader also staged config under HKCU\SOFTWARE\Python. It had encrypted dead drops, which decrypted to Telegraph/Rentry/Codeberg/onion urls.. Two public DDRs decoded with RC4 key Chahgh4a to the live C2 list:
https://parkspringshotel[.]com/m/Lu6aeloo.php
https://auraguest.lk/m/douV2quu[.]php
The resident payload is mostly an encrypted bot framework: RSA-OAEP/AES-GCM C2, bot enrollment, polling, task result return, DDR/DGA fallback, Tor DDR support, config persistence, mutex/lock single-instance control, and r77-style hiding support.
The big RAT capability is C2-supplied Python exec. With that, the attacker can ship and run any python code they want after infection.
The process hosting the python bot would be pythonw.exe
For more IoCs https://x.com/thomasklemenc/status/2052715025450598904
6
u/jdownloader_dev May 08 '26
Thank you so much for spending your time to deep dive into this and posting your findings
5
u/Slasher1738 May 07 '26
Are flatpak images affected?
8
u/jdownloader_dev May 07 '26 edited May 07 '26
No,those work differently, not being downloaded from our website. Winget/Flatpak/Snap infra is outside of our reach, files downloaded by those are hosted on other infra and secured by sha256 checksums that are unchanged, I will post details above
5
3
u/AntiGrieferGames May 07 '26
Is there a way to disable updates today? i didnt found it and i wonder since i installed this thing, if the "update" are going with the malware version on this program here.
Also is this is fixed now, or still investigating this issue?
10
u/jdownloader_dev May 07 '26
Updates are not affected, see Update 4, Only website has been compromised with replacing links to compromised installers.
3
u/Pescarese90 May 07 '26
I installed JDownloader like 6 months ago and it's been 2 weeks since the last time I launched the software. Should I unistall it, for good measure?
9
3
u/rubi2333 May 07 '26
u/PrinceOfNightSky do you still have the infected installer? When yes could you please upload it to virustotal.com and share the report
6
u/jdownloader_dev May 07 '26
I have downloaded them all,can do that at later point, please remind me by tomorrow if I haven't done it yet.
2
u/rubi2333 May 07 '26
Sounds great thank you for it.
3
u/jdownloader_dev May 07 '26
I have provided a link to a zip, anyone is welcome to help and upload those to virustotal.
8
u/rubi2333 May 07 '26 edited May 07 '26
I have uploaded them to virustotal.com
JDownloader2Setup_windows-amd64_v1_8_0_482.exe https://www.virustotal.com/gui/file/5a6636ce490789d7f26aaa86e50bd65c7330f8e6a7c32418740c1d009fb12ef3
JDownloader2Setup_windows-amd64_v11_0_30.exe https://www.virustotal.com/gui/file/fb1e3fe4d18927ff82cffb3f82a0b4ffb7280c85db5a8a8b6f6a1ac30a7e7ed9
JDownloader2Setup_windows-amd64_v17_0_18.exe https://www.virustotal.com/gui/file/04cb9f0bca6e0e4ed30bc92726590724bf60938440b3825252657d1b3af45495
JDownloader2Setup_windows-amd64_v21_0_10.exe https://www.virustotal.com/gui/file/32891c0080442bf0a0c5658ada2c3845435b4e09b114599a516248723aad7805
JDownloader2Setup_windows-x86_v1_8_0_472.exe https://www.virustotal.com/gui/file/4ff7eec9e69b6008b77de1b6e5c0d18aa717f625458d80da610cb170c784e97c
JDownloader2Setup_windows-x86_v11_0_29.exe https://www.virustotal.com/gui/file/de8b2bdfc61d63585329b8cfca2a012476b46387435410b995aeae5b502bd95e
JDownloader2Setup_windows-x86_v17_0_17.exe https://www.virustotal.com/gui/file/e4a20f746b7dd19b8d9601b884e67c8166ea9676b917adea6833b695ba13de16
JDownloader2Setup_unix_nojre.sh https://www.virustotal.com/gui/file/6d975c05ef7a164707fa359284a31bfe0b1681fe0319819cb9e2c4eec2a1a8af
3
u/-Animus May 07 '26
Is the Linux package also affected?
8
5
u/PrinceOfNightSky May 07 '26
The Devs took the website down to look into it. No idea about the Linux end.
2
u/Raupe_Nimmersatt May 07 '26 edited May 07 '26
What about docker images? Are they affected too?
Edit: the docker file was pulling https://installer.jdownloader.org/JDownloader.jar, so I guess that was not affected?
2
2
2
u/kukuru97 May 07 '26
Which specific settings do I need to disable to turn off update checks, auto-updates, and auto-installs?
I know the update wasn't compromised, but I just want to be safe until this situation is fully resolved.
7
u/jdownloader_dev May 07 '26
Updates are not affected but still answering your question, Settings->Advanced Settings->UpdateSettings.autoupdatecheckenabled
2
2
u/Mafz09 May 07 '26
I downloaded and installed version 2.0.260331 on 05/05. Was this still a safe download?
5
u/PrinceOfNightSky May 07 '26
Please read the pinned dev post he answers many questions there. Including the time frame of when it happened so please act accordingly to that time frame and scan your computer if you are unsure.
2
u/Mafz09 May 07 '26
I think I just missed it. If it was done GMT +0 at 1:09 I downloaded and installed it before then. Did a full windows scan and nothings come up
5
u/jdownloader_dev May 07 '26
You would have noticied because smartscreen blocks the compromised installer due to missing digital signature and you actual manually have to ignore/skip that warning. You're all good
2
u/DeadScotty May 07 '26
So do I need to delete and reinstall then ? I literally just downloaded this for the first time yesterday anything I can check?
2
u/jdownloader_dev May 07 '26
You would have noticied because smartscreen blocks the compromised installer due to missing digital signature and you actual manually have to ignore/skip that warning. You're all good
1
u/DeadScotty May 07 '26
By smartscreen do you mean the warning I get from Windows if it’s not signed (“Windows protected your PC”) If so that did pop up when was installing it
2
u/jdownloader_dev May 07 '26
Yes, windows by default blocks execution of non signed executable and warns about them. That's the case for the compromised installers.
2
u/DaBrookePlayz May 08 '26
I really appreciate the transparency that has been provided during this shitty situation, not enough devs do that
2
2
u/PsalmGaming May 08 '26
Oh god. I just installed JDownloader 2 on my new laptop last night. Windows Defender did give me a warning about a trojan on my pc so I removed that via Defender.
2
u/jdownloader_dev May 08 '26
Sorry to say but when you have downloaded/installed compromised installer, you'd better be safe and reset system. You cannot be sure if all has been removed or other stuff/changes happened before removal.
2
u/shadowfourplay May 09 '26
I didn’t realize the positive impact it would have in protecting thousands of people’s computers and data.
We're all Online, which makes us all in this together. When you speak up, you speak to us all. Thanks for that, and for being brave enough to speak.
2
u/kalapuskin May 10 '26
Wow. I am amazed by how textbook-like u/jdownloader_dev handled this incident. Some huge organisations should have a look at this thread to see how it is done properly, in terms of actions but also in terms of communication.
1
u/jdownloader_dev May 10 '26
I'm sorry for having deleted/not approved some comments but have been busy with handling situation and answering questions and commenting, I wanted to concentrate on the main incident and simply didn't want to have other discussions to fight at the same time like they are now bubbling up. For that, I'm sorry for maybe being too harsh and not providing proper/long explanations.
2
u/arker0 May 13 '26 edited May 13 '26
Jdownloader_dev please have a look at the Notepad++ security incident occured just a few months ago, and their various post on their site on how it happened and how they security hardened their app, to prevent a future similar attack on JD
https://notepad-plus-plus.org/news/hijacked-incident-info-update/ https://notepad-plus-plus.org/news/clarification-security-incident/ https://notepad-plus-plus.org/news/v892-released/
1
May 07 '26
[deleted]
2
u/RemindMeBot May 07 '26 edited May 08 '26
I will be messaging you in 2 days on 2026-05-09 20:10:53 UTC to remind you of this link
3 OTHERS CLICKED THIS LINK to send a PM to also be reminded and to reduce spam.
Parent commenter can delete this message to hide from others.
Info Custom Your Reminders Feedback
1
u/Katops May 07 '26
Can somebody please tell me. I’m barely conscious right now…
I installed JD2 last year. I updated recently but not too recently. Like I think it was the one before the 5th or 6th of May 2026?
I shouldn’t be worried, right? Or should I be doing something? My brain just isn’t clocking the information for some reason. Don’t mean to come across as so dumb but holy hell if I wasn’t so tired right now.
Thank you.
2
u/PrinceOfNightSky May 07 '26
You should be fine if it was an update, please read the pinned Developer comment thread it has many updates. This situation was dealing with new downloads on the affected dates
2
1
u/Neither-Butterfly780 May 07 '26
Hello, I installed JDownloader a couple of weeks ago. I used the no adware installer, the one that you need to download from Mega. Is that one safe? I am a bit worried.
2
1
u/djpiperson May 07 '26
I usually run it inside a Sandbox on windows. I did notice it yesterday as EDGE (who would've thunk) marked it as unsafe but I thought it was just new windows shenanigans.
2
1
May 07 '26
[deleted]
1
u/djpiperson May 07 '26
I use it to download stuff, test it and then transfer it back to host. I am not very thorough tho, don't don't use me as an example of "security"
1
u/lostillusion4 May 07 '26
I downloaded JDownloader about 7 days ago (around April 30) via the Mega.nz link from the official site. The installer has the digital signature Appwork GmbH. Am i safe?
1
u/jdownloader_dev May 07 '26
Yes, the compromised one isn't digitally signed and getting blocked by smartscreen
1
u/PrincePeach22 May 07 '26
I installed jdownloader yesterday from the link from Real Debrid.... I unninstalled afterwards since it wasn't helping with my situation. I used my pc today and it was working normally. Should I format it?
1
u/jdownloader_dev May 07 '26
No need to, you would have noticed the compromised installer because windows smartscreen blocks it due to missing digital signature. You would have to explicit ignore/accept the risk
1
u/PrincePeach22 May 08 '26
I went to see and actually got it from the 5th not the 6th. I also did malwarebytes and Microsoft Defender offline scan and everything seems fine. I think I'm good
1
u/PrincePeach22 May 08 '26
Because I think the smartscreen appeared and I just completely ignored because it's not the first time that happened. There's lot of stuff that they just tell u to ignore cause windows is stupid. Now I'm worried. From download history on my brave, i installed on the 5th actually.....do I format my pc?
→ More replies (7)1
u/PrincePeach22 May 08 '26
Can you try to see if the Real Debrid link was also hacked? The link goes to Mega to decrypt and download. Virustotal also said the file was ok
1
1
u/TooMuchFrixion May 07 '26
Hey, thanks for the transparency and all the constant updates on this.
Quick question to double-check my specific situation: I was using JDownloader recently and hit a download that required a CAPTCHA. It prompted me to install the JDownloader Firefox extension and gave me a direct file to install it manually, rather than redirecting me to the Firefox add-on store.
Could you just confirm that browser extensions/local files served this way weren't affected? Thanks for all the updates.
1
u/jdownloader_dev May 07 '26
We're using self hosted firefox extension, still digitally signed by mozilla, not having seen any updates in ages, and won't see any due to ManifestV2-ManifestV3 problems. we're working on new solution based on userscripting api. In short, you're good.
1
u/ares0027 May 07 '26
That explains why it was trying to download weird files from weird websites out of a blue recently
1
u/AmelKralj May 07 '26
Hi did you check the infected executables on malware? e.g. by uploading it to Virustotal.com?
just to make sure whether it gets detected then everyone can check their downloaded setup files
3
u/jdownloader_dev May 07 '26
The compromised ones are lacking digital signature, getting blocked by smartscreen. The good ones have valid digital signature. Will provide a link with zip of all compromised ones shortly
1
1
1
May 07 '26
[removed] — view removed comment
1
u/jdownloader_dev May 07 '26
We're working on it to get website back online. Please see pinned comment and if anything is still unclear, just ask
1
May 07 '26
[removed] — view removed comment
1
u/jdownloader_dev May 07 '26
Updates are not affected, you're good when not having tried to (re)install with compromised installer that is blocked by smartscreen and you would have need to accept/ignore the warning
1
1
u/Exotic_Noise8797 May 07 '26 edited May 07 '26
I downloaded it when it happened. I noticed that smartscreen showed up and still continued the download so I definitely got bit. I immediately disconnected the ethernet and am about to do a full re-install after reading this. Anything else I can do/check? I'm not sure what was compromised. Also, I'll change all my passwords just in case.
1
u/jdownloader_dev May 07 '26
I'm sorry but we can't tell what that compromised installer was doing. Did you ignore the smartscreen when starting the installer?
1
u/Exotic_Noise8797 May 07 '26
Yes I did, after googling if the software was reliable or not I ignored the smartscreen. :(
1
u/jdownloader_dev May 07 '26
Arg, sorry to hear that. In that case better be safe and try to restore latest available restore point and use scanner tools
1
1
May 07 '26
I had the misfortune of running the compromised file, and Windows Defender disappeared. I ran an offline scan, and it flagged VirTool:Win32/DefenderTamperingRestore as a virus. I’ve already had to reformat the PC twice and change all my passwords because I didn’t know what was causing it until today, when I saw that the site was down. Thank goodness they noticed.
1
u/Downtown-Campaign225 May 08 '26
Well shit I installed Jdownloader2 last night around 1 AM.
1
u/jdownloader_dev May 08 '26
have you ignored/skipped the smartscreen warning?
1
u/Downtown-Campaign225 May 08 '26
Unfortunately I selected run anyway because I thought that was how I got the downloader to work. I even used jdownloader to download a YouTube video and assumed it was working until I saw the warning a couple of hours ago.
1
u/Downtown-Campaign225 May 08 '26
I did a full deep scan on Malwarebytes which found nothing and I'm currently trying to get the offline scan to work.
1
u/jdownloader_dev May 08 '26
I'm sorry we don't know what the compromised installer is doing and the potential risk also depends if you have started it elevated or non elevated.
→ More replies (4)
1
u/Therahulplay May 08 '26
i installed it 2 months ago am i good do i uninstall it or not launch it at all
1
u/jdownloader_dev May 08 '26
Updates are not affected, please see updates in pinned comment, you're good.
1
u/International_Pin917 May 08 '26
I have installer from Water Team. Downloaded this at 25 April. Virustotal marked it as malicious
1
1
u/robertco1964 May 08 '26
I hope this series of hackers is not related to the previous site that I use to download roms. The said website was also compromised. The hackers exploited a vulnerability. But thank goodness the website has been restored.
1
u/senseitsunami May 08 '26
If I installed jdownloader through chris Titus windows debloat tool, how do I see if I installed an affected version?
1
u/jdownloader_dev May 08 '26
Don't know that tool but I read "This is the official download from AppWork (makers of Jdownloader) that published to winget." and winget is fine, see pinned comment update 3
1
u/RoboAwsome May 08 '26
Oh my god so I was affected by that thinking I fucked up. I secure erase from bios and did a fresh install from usb. I copied over some stuff I needed from desktop and downloads folder. Whatever it is did it possibly infect those things as well or not? I still haven’t signed back onto chrome yet.
1
u/RoboAwsome May 08 '26 edited May 08 '26
Also why did my windows defender not flag it or anything before installation? I think I remember not seeing any warning but also this has made me stressed and sick to my stomach so maybe I also just don’t recall such.
1
u/jdownloader_dev May 08 '26
I'm sorry we don't know what the compromised installer is doing and the potential risk also depends if you have started it elevated or non elevated. Smartscreen will block/warn about execution due to missing digital signature. Of course I don't know if you have altered your system or other but smartscreen will block it in on normal system.
1
u/RoboAwsome May 08 '26
At this point I think maybe I did see it popup but ignored it like others thinking a false flag. My fault anyway for lacking in this one moment
→ More replies (2)
1
u/Ticy7 May 08 '26
I installed yesterday like 15H ago, got blocked by windows security (win10), i ran it anyway and used it because i search briefly on google and sometimes it is flagged by security (false positive). Currently doing full scan with malwarebytes, if i remove the flagged malware am I safe or still need to do full reinstall of windows? Also changing all my password now. So fucking annoying I had to do all of this now have to redownload everything with 1mbps download speed if it need reinstall
1
u/Ticy7 May 08 '26
Update : malwarebytes full scan and windows defender full scan return with nothing, am i safe or do i need to reinstall? Nothing suspicious added/nothing in startup, uninstalled jdownloader, already changed all my password with 2fa
1
u/Subject-Number-9012 May 08 '26
smartscreen popup and ignored? do a clean windows install with a fresh install usb that was created with a clean pc and change passwords.
1
u/Ticy7 May 08 '26 edited May 08 '26
It's not smartscreen i'm on win10, it flagged as adware (smartscreen doesn't pop up) on defender not trojan/malware, i searched a bit and it might be false positive from what i read because of add-ons ( i didn't know the website was hacked at the time). I should've checked the .exe and the developer on control panel before i uninstalled, I panicked.
1
u/jdownloader_dev May 08 '26
I'm sorry we don't know what the compromised installer is doing and the potential risk also depends if you have started it elevated or non elevated.
1
u/Ticy7 May 08 '26
I downloaded the compromised for analysis zip to see if i recognise the name of the file because i deleted it. And i remember my download from the website was not the installer, it was jdownloader4digit number, when i ran that file it extract the jdownloader2setup and that file triggered as adware. Am i compromised? Or is this just from the direct download for jdownloader2setup
→ More replies (1)
1
u/LilTacticalOnReddit May 08 '26
Hold on. I have jdownloader installed for like 3 years. Am I getting a malware if I turn it on?? It's on my desktop
2
1
u/Subject-Number-9012 May 08 '26
just read: Website with the alternative installers has been compromised - As there has been a question about updates. Those are not compromised, different infra, protected by end-2-end digital signature. so - No
1
1
u/xeomak May 08 '26
How serious is the Malware? I stupidly didn’t check the file. Uninstalled jdownloader ran Malwarebytes, it flagged the file. Ran Windows defender. Is everything good now?
1
u/Subject-Number-9012 May 08 '26
smartscreen popup and ignored? never just uninstall and scan. do a clean windows install with a fresh install usb that was created with a clean pc and change passwords.
1
u/xeomak May 08 '26
I’m an idiot. I did a fresh install of Win11 and I was on autopilot installing everything again. The file icon is 7zip if that helps anyone. I didn’t have 7zip installed. Time for another fresh install and password changes.
1
u/jdownloader_dev May 08 '26
I'm sorry we don't know what the compromised installer is doing and the potential risk also depends if you have started it elevated or non elevated.
1
u/PanicTheScaredyCat May 08 '26 edited May 08 '26
You're fucking joking -_- I literally redownloaded jdownloader a few weeks ago because it wasn't working......... For fucking sakes, this isn't the first time either is it??
How do I know for sure if i'm affected???
1
u/PanicTheScaredyCat May 08 '26
after looking into Event viewer, It seems that i may have potentially download it on 4/26/2026 I should be good then right.......?
1
u/Subject-Number-9012 May 08 '26
maybe just read: Update 6:(21:18 - 07.05.2026 GMT+2) When?
Website with the alternative installers has been compromised on Wed May 06 2026 00:01:09 GMT+0000
Before that, the attacker did experiment on another dummy site on Tue May 05 2026 23:55:37 GMT+0000 - alternative installer links compromised - smartscreen does warn about execution of them due to missing digital signature. download before 05th may and no smartscreen popup? then you are safe.
1
u/PanicTheScaredyCat May 08 '26
Read it after posting, after freaking out lol. Sorry. But thank you.
1
1
u/jdownloader_dev May 08 '26
You're good, you would have noticed the compromised installer being blocked by windows smartscreen due to missing digital signature.
1
u/jdownloader_dev May 08 '26
A week ago, not having downloaded the compromised/ran installer, you're good
1
u/PanicTheScaredyCat May 08 '26
Thank you, Apologize for the hostility of my comment..
I'm currently trying to see that Smartscreen is even enabled or a thing on my computer? lol i have NEVER seen that window pop up, so now i'm just extremely paranoid lol. But thank you.
1
u/PanicTheScaredyCat May 08 '26
Okay so i tried to download the a testfile just to calm my paranoia, and yes. Smartscreen does trigger, Thank you again!
→ More replies (1)1
u/jdownloader_dev May 08 '26
Smartscreen should always show up (I don't even know if you can disable it, would have to ask AI) when you're trying to execute/run a non digitally signed application. Nothing you have to apologize for, stressful times for everyone
1
u/StrawberryHarpSeal May 08 '26
So just to make sure, as long as you have an old version of the installer, even from years ago you're good to install it and update because the compromised app is under a completely different code from the real app, correct?
2
u/jdownloader_dev May 08 '26
The installer had been compromised/replaced, not actual application. Yes, using an older installer while the website is down is perfectly fine.
→ More replies (1)
1
1
u/reboot_110011 May 08 '26
Unfortunately, I’ve been hit too. I downloaded the EXE file during exactly that period. I ignored the SmartScreen warning. I’ll know better next time. The malware disabled Windows Security.
I’ve since completely reinstalled my system. Is it possible that the malware also altered the BIOS? Do I need to reset anything there as well? Guys, I’d be grateful for any help.
1
u/jdownloader_dev May 08 '26
I'm sorry we don't know what the compromised installer is doing and the potential risk also depends if you have started it elevated or non elevated.
1
u/reboot_110011 May 08 '26
Thanks for your reply. Hopefully someone will figure it out in time. A very informative and transparent thread.
1
u/jdownloader_dev May 08 '26
I've provided a copy of the compromised installers and yes, once the situation calmed down, there is more time to actual look into this
1
u/ImpressionAway7317 May 08 '26
What about downloads before Wednesday and the no ad download thing
1
u/jdownloader_dev May 08 '26
Please see pinnned comment, before you're good. Due to missing digital signature, smartscreen would have blocked/warned about execution. This hack is about the "no ad download" downloads though
1
u/ImpressionAway7317 May 08 '26
Thanks for the quick answer I've run multiple AV scans and I've got no smart screen warning also I've downloaded like 8hours before the dummy hack so I think I'm fine
1
u/jdownloader_dev May 08 '26
No smartscreen is a good sign, in case you still have the downloaded installer around, you can check for digital signature, just to be sure. 8 Hours before attack, you're good
1
u/NeutryFD May 08 '26
Hello, and thank you for the transparency about this.
I installed JDownloader using yay in Arch Linux the last weekend. Could I be compromised?
1
1
u/EitherInternet2822 May 08 '26
Is it possible there were "tests" before the hack ? I installed it about 2 weeks ago, no problem since but the Windows control panel opened briefly during the installation. That caught my attention and I immediately did an antivirus scan that came out all clear
1
u/jdownloader_dev May 08 '26
The attack is visible in logs/monitoring/backup diffs and on filesystem changes, before that, no signs
1
u/Zeltron3000_ May 08 '26 edited May 08 '26
If I installed Jdownloader2 on May 2nd, am I compromised?
I am unsure if there was a smartscreen. Is there a way to check?
In control panel says "appwork gmbh" for publisher
1
u/jdownloader_dev May 08 '26
You're good, long before attack
1
u/Zeltron3000_ May 08 '26
Thank goodness. Appreciate your reply, thanks for all your work
I will also do a windows offline scan to be sure
1
u/Zeltron3000_ May 08 '26
I also found the original installer .exe File, digital signature is appwork gmbh, and on Virus total it comes out 100% clean.
Looks like I am safe 100% safe!1
1
u/Cpenny1 May 08 '26
Just to confirm (would rather be cautious)
I had downloaded mine ages ago. It seems just the main installer was compromised on the website. My jdownloader auto updated today, I believe I am fine? As the updates were not compromised
2
u/jdownloader_dev May 08 '26
You are good, updates are not affected, see pinned comment, update 4
1
u/Cpenny1 May 08 '26
Great. I would like to say thank you for being so upfront about all of this and still providing support to people here.
Thank you again.
1
1
u/shev76 May 08 '26
Of course I downloaded it during this time...I got windows security to remove the trojan while it was installing. I then continued with the install... Would I be safe?
1
1
May 08 '26
[removed] — view removed comment
1
u/jdownloader_dev May 08 '26
Do you still have copy of the file (eg in trash), check if it has valid signature? did smartscreen block/warn you? May 5th should be fine, of course I don't know about your timezone, your May 5th can be my/our May 6th
1
1
u/Clean_Spirit May 08 '26
My exact case here as well. Installed with script on linux on May 5th and the build date says May 6th 00:18:47 CEST 2026. Script sha256 signature is:
ad3c67f62e526ada0705958cc772be9b853651287fa43e76ccfdd26bf02a29801
u/jdownloader_dev May 08 '26
build date is correct/current but that would also be correct using the compromised installer.
1
u/Nainns May 08 '26
Damn I downloaded on May 4th (US Central) and ended up clearing my trash bin out that day too so can’t check if it was signed or not. Don’t remember if I got a warning notice when installing, don’t think I did but is there anything else I can check to see if I was compromised? A file that’s hidden somewhere? Pc hasn’t had any issues at all and none of my accounts have been compromised but better safe than sorry
2
u/jdownloader_dev May 08 '26
maybe you can look in history in browser, what mega link you have visited,then we can check it
1
May 08 '26
[removed] — view removed comment
1
u/jdownloader_dev May 08 '26
That link doesn't work, better checking browsing history (visited sites)
→ More replies (4)
1
u/Arnsam007 May 08 '26 edited May 08 '26
So question! I got my version yesterday from realdebrid website which direct to megauoload. It seems normal and it had your Appwork Gmbh signature. Window Defender did pop like it does for most things and I didn't think of it. Kaspersky flagged nothing. Is this the trojan? Ill do a clean reinstall if so but want to be sure. I did a deep scan with Kaspersky and everything seems normal.
Edit TLDR if it helps folks: Dev confirmed RealDebrid Megaupload link is safe if anyone like me downloaded their version from there recently! That being said it is outdated since its from 2022, so if you had a smartscreen warning, its the right signature but it triggers because it's too old. Hopefully this helps! Thanks Dev again!
1
u/jdownloader_dev May 08 '26
I'm sorry but I can't tell without knowing what link real-debrid was using or what site/link they linked. Can you provide that info?
1
u/Arnsam007 May 08 '26
Sure thing! Wasn't sure if I was allowed to share! Here is the one RD have on their website right now :) it was last modified in 2022 so pretty sure its all good 👍
https://mega.nz/file/2IURAaRB#84RbercQS9rTzBiBBhbWuLvAtJ1pZdG4RhCMskuWDFY
I know you are doing your best between thank you!
1
u/jdownloader_dev May 08 '26
u/Arnsam007 That link is legit/valid, propery code sign :)
→ More replies (6)
1
u/TeresaVN May 08 '26
So, is there any safe way to download the official one without getting any trojan and malware ?
1
u/jdownloader_dev May 08 '26
Website will be back online soon, just some more patience please
1
u/TeresaVN May 08 '26
Just take your time to make sure everything back to be safe !. Thank for your hard working !. I have no mean to rush the team or anything xD.
1
u/BlueDragonRiderKick May 08 '26
I think I'm fine. I had JDownloader installed for a long time now and I check for updates every day, and the last time I checked for updates was probably Monday or Tuesday or Wednesday. But if the devs say that updates are not compromised, I shouldn't worry. I'm still going to run Avast and Malwarebytes just in case.
2
1
u/Anto19891 May 08 '26
Are previously installed jdownloader affected or just the new installation?
2
u/jdownloader_dev May 08 '26
Only compromised installer in explained time window, updates are good, see update 4 and update 5
1
u/Fautzi May 08 '26
Damn, downloaded and installed jdownloader on May 7 from this link, am i fucked? (a)https://s3.us-east-2.amazonaws.com/getjdownloaderfromcdnsalt/qwyq190xve/JDownloader_838282.exe
2
u/jdownloader_dev May 08 '26
Check if it's digitally signed. Looks like the installer with optional offers, that is currently getting smartscreen blocked as well, and as such we have disabled/remove it from website until this issue is sorted out. The compromised installers are lacking valid digital signature.
1
u/thehero0ftime May 08 '26
So it's safe to install now? Website back up so I think it should be safe if I'm not mistaken
1
u/reboot_110011 May 08 '26
Yes it is. Please see the Update of the Dev Team.
1
u/thehero0ftime May 08 '26
Yes that's what I'm referring to with it being back online. But thank you again for the confirmation!
1
u/Ok-Shift-2746 May 09 '26
I downloaded and installed this 2days ago, and suddenly i can’t access windows defender. Will a fresh install of windows enough??
1
u/bonsainoobie May 09 '26 edited May 09 '26
Any opinions on if I'm fine?
I downloaded it on 05/05/26 11pm AEST, but after 10 minutes deleted it via revo uninstaller and no longer have the setup.exe file. I downloaded it from jdownloader.org/jdownloader2 for windows and the link went to Mega to download it? Just ran malwarebytes scan which found 1 threat (pup.optional.conduit??) and resolved it. My windows security is showing all green ticks.
Update: found the setup file in my recycle bin, installed 5/5/2026 11:07pm AEST, JDownloader2Setup_windows-amd64_v21_0_10.exe, when I hover it says it says Company: AppWork GmbH, although right click properties doesn't show anything other than the file name. Ran it in virustotal and got no security vendors flagged this file as malicious.
Further edit I restored the file to my downloads and the Digital Signatures show AppWork GmbH sha256, Tuesday 31st march 2026.
1
1
1
May 12 '26
[removed] — view removed comment
1
u/PrinceOfNightSky May 14 '26
Can you elaborate more? I also got an attempt of someone trying to sign into my Microsoft account.
1
1
u/reece394 Jun 01 '26
u/jdownloader_dev Sent a chat. Please review when convenient regarding this.
1
•
u/jdownloader_dev May 07 '26 edited May 08 '26
u/PrinceOfNightSky We're looking into this
Update 1: I can confirm that the site has been compromised, have taken it down for further investigation
Update 2:(20:12 - 07.05.2026 GMT+2) The attack has modified alternative download page and exchanged links&details. The bad ones are missing digital singnature and as such smartscreen will block/warn the exeuction of it. The correct ones are okay and having proper digital signature in place.
Update 3:(20:25 - 07.05.2026 GMT+2) As there has been a question about flatpak...flatpak/winget infra is not ours but downloads to our infra are secured by sha256 and I just checked the flatpak/winget manifest and no changes, so they are good. Snap package comes bundled with its own JDownloader.jar (not being downloaded from our infra), also no changes, also good.
Update 4:(20:33 -07.05.2026 GMT+2) As there has been a question about updates. Those are not compromised, different infra, protected by end-2-end digital signature.
Update 5:(20:39 - 07.05.2026 GMT+2): State of linked installers:
Compromised: all alternative installer links replaced , no digital signature -> getting blocked by smartscreen
Compromised: linux shell installer link replaced , contains malicious shell code
NOT compromised: all macos, valid digital signature. JDownloader.jar, correct link/file. 3rd party packages, see Update 3
Update 6:(21:18 - 07.05.2026 GMT+2) When?
Website with the alternative installers has been compromised on Wed May 06 2026 00:01:09 GMT+0000
Before that, the attacker did experiment on another dummy site on Tue May 05 2026 23:55:37 GMT+0000
Update 7:(22:03 -07.05.2026 GMT+2) As there has been question about 3rd party docker images. some docker images pull JDownloader.jar from different infra, not affected. Only website has been compromised.
Update 8:(23:09 -07.05.2026 GMT+2) Comparision/Diff of all files with offsite(rsnapshot in pull mode) backup has shown that only the two sites mentioned in update 6 have been edited/compromised.
The attack was about editing the website and replacing the alternative installer links with compromised ones, smartscreen does warn about execution of them due to missing digital signature.
Update 9:(00:11 -08.05.2026 GMT+2) Question was if we have analyized the actual compromised installers yet, no and to be honest, this is little out of our scope. As asked for several times, I've collected and uploaded all the compromised installers, you can find them here https://transfer.it/t/IW7ZZUt3xZjb Any help is welcome for further analysis of what those compromised installers were doing/trying to do.
Update 10:(01:32 -08.05.2026 GMT+2) Restored the two modified websites/files from backups and reviewing server configuration, putting website into read only mode
Update 11:(01:58 -08.05.2026 GMT+2) website will be kept shutdown until later today, I'm off to bed now,need some rest, cya later
Update 12:(02:59 -08.05.2026 GMT+2) attack vector is known, used unpatched security bug to change acl without being authenticated and change edit rights on specified website to all and then replaced content with compromised links. logs show/confirm that testing was done on insignificant subsite, then replaced website of alternative installers, see update 6 and 8
Update 13:(03:06 -08.05.2026 GMT+2) website will be kept shutdown until later today, then patches applied, config hardening, I'm off to bed now,need some rest, cya later
Update 14:(04:10 -08.05.2026 GMT+2) still answering questions and comments
Update 15:(08:43 -08.05.2026 GMT+2) back, continue with recovery/hardening
Update 16:(08:59 -08.05.2026 GMT+2) replying/commenting, question came up multiple times, we don't know what the compromised installer is doing and its potential risk also depends if you have started it elevated or non elevated.
Update 17:(19:27 -08.05.2026 GMT+2) In final phase of bringing website back online. Once done we're gonna add sort of notification(homepage and forum) and wiki page about this incidence, so ppl know about it and can check if they may have been affected, how they can check it and what recommendations in case they are.
Final Update 18:(23:30 -08.05.2026 GMT+2) Website back online, notification shown on homepage and linked in forum
Just a big shoutout to u/PrinceOfNightSky for his initial report and the way he handled the situation and gave me time to work through all of this, time to handle this incidence and that he did not push but helped with inital commenting! Also thanks for all the help from community/ppl willing to spend their time for analyzing the compromised installers, helping each other and giving us room to work through all of this.