JDownloader site hacked to replace installers with Python RAT malware

2026-05-10T01:23:28Zd05db12100df2e778c107455ef2495fe5ab227c5b36d2ec87c182d252eb446ad
CISACanvas defacementDirty FragHugging FaceIvanti EPMMLinux privilege escalationNVIDIA GeForce NOWOpenAI impersonationPCPJackRansomHouseTCLBankerTeamPCPVidar stealerWhatsApp propagationcredential theftdata breachinfo stealermalicious installerpython RATremote access trojanshinyhunterssoftware supply chainsource code leakwebsite compromisezero-day

What happened

Multiple high-risk incidents reported: the JDownloader website was compromised to serve malicious Windows and Linux installers (Windows payload a Python-based RAT); a fake OpenAI repo on Hugging Face distributed an info‑stealer; NVIDIA confirmed a GeForce NOW data breach affecting Armenian users; Trellix source-code was claimed by RansomHouse; and multiple zero-days were disclosed/exploited — notably a high-severity Ivanti Endpoint Manager Mobile (EPMM) RCE used in active attacks (CISA issued an urgent patch directive) and a new Linux local-privilege escalation dubbed “Dirty Frag.” Additional,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
d05db12100df2e778c107455ef2495fe5ab227c5b36d2ec87c182d252eb446ad
Enrichment time
2026-05-10T01:23:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.