Official JDownloader site served malware to Windows and Linux users between May 6 and May 7

2026-05-10T14:51:51Z06be05941ba06651d3ff4b3459e4e3147cbc79672f30b44b4df257584cee5771
api-keysaws-credentialsbackdoored-packagecloudz-ratcredential-theftdata-breachdirty-fragics-attackjdownloaderkernel-privilege-escalationlinux-ratmalwareotp-theftprivilege-escalationpython-ratpytorchqlnxransomwaresupply-chain-attackwater-sector

What happened

Between May 6–10, 2026 multiple security incidents and research disclosures highlight a surge in supply-chain compromises, Linux-targeting implants, and an exploited local kernel flaw. The official JDownloader site was compromised (May 6–7) and served malicious Windows and Linux installers embedding a Python RAT. Researchers disclosed Quasar Linux RAT (QLNX), a fileless Linux implant targeting developers for credential theft, keystroke logging and persistence. A new unpatched Linux kernel local privilege-escalation vulnerability nicknamed “Dirty Frag” has a public working exploit affecting多数/​

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
06be05941ba06651d3ff4b3459e4e3147cbc79672f30b44b4df257584cee5771
Enrichment time
2026-05-10T14:51:51Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.