The official Xubuntu website was compromised over the weekend (18/19 October 2025) briefly serving up Windows malware to users trying to download the distro.
Users who visited the Xubuntu website over the weekend to download the official.torrentof the Xfce-toting Ubuntu flavour instead got axubuntu-safe-download.zip.
When the rogue zip file was extracted it contained an.exeruntime and a ‘terms of service’ text file.
The Xubuntu team took down the affected download page as soon as they were informed. There is no indication that direct Xubuntu ISO downloads (or checksums) were modified, altered, replaced or otherwise interfered with.
The malicious download link appears to have been live for a day or two at most. Wayback Machine snapshots from 11 October point to the .torrent file, but the 18 October snapshot offers the malicious .zip instead.


