Official JDownloader site served malware to Windows and Linux users between May 6 and May 7
2026-05-10T14:51:51Z•06be05941ba06651d3ff4b3459e4e3147cbc79672f30b44b4df257584cee5771
api-keysaws-credentialsbackdoored-packagecloudz-ratcredential-theftdata-breachdirty-fragics-attackjdownloaderkernel-privilege-escalationlinux-ratmalwareotp-theftprivilege-escalationpython-ratpytorchqlnxransomwaresupply-chain-attackwater-sector
What happened
Between May 6–10, 2026 multiple security incidents and research disclosures highlight a surge in supply-chain compromises, Linux-targeting implants, and an exploited local kernel flaw. The official JDownloader site was compromised (May 6–7) and served malicious Windows and Linux installers embedding a Python RAT. Researchers disclosed Quasar Linux RAT (QLNX), a fileless Linux implant targeting developers for credential theft, keystroke logging and persistence. A new unpatched Linux kernel local privilege-escalation vulnerability nicknamed “Dirty Frag” has a public working exploit affecting多数/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 06be05941ba06651d3ff4b3459e4e3147cbc79672f30b44b4df257584cee5771
- Enrichment time
- 2026-05-10T14:51:51Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.