Threat reportSupply ChainTL-2026-0608

forge-jsxy npm Supply Chain RAT — 22 Versions in 22 Days with Crypto Wallet Theft, WebRTC P2P Exfil & Cross-Platform Persistent Backdoor (OSV MAL-2026-3609, SafeDep)

highACTIVE

forge-jsxy npm Supply Chain RAT (TL-2026-0608), also tracked as forge-jsxy RAT, is a high-severity supply-chain compromise, first published 2026-05-27. It has no confirmed attribution, affects npm Registry forge-jsxy, maps to 37 MITRE ATT&CK techniques (T1005, T1036.005, T1041), and is covered by 9 detection rules and 22 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
37MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
22Indicators of compromise

Key facts for TL-2026-0608

Threat ID
TL-2026-0608
Also known as
forge-jsxy RAT, forge-jsx RAT, MAL-2026-3609, jacksonkaandorp2 npm campaign
Severity
HIGH
Status
ACTIVE
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
technology, software development, cryptocurrency, fintech, open source ecosystem, devops
Target regions
Global
Detection rules
9
Indicators of compromise
22

Malware and tooling in forge-jsxy npm Supply Chain RAT

Malware and tooling: forge-jsxy RAT, Custom Node.js RAT with WebSocket+HTTP+WebRTC+Discord exfil

How forge-jsxy npm Supply Chain RAT works

Malicious npm package forge-jsxy (successor to forge-jsx) published 2026-05-04 by operator jacksonkaandorp2 shipped 22 versions in 22 days impersonating an Autodesk Forge SDK integration. A postinstall script deploys a hidden cross-platform RAT that harvests keystrokes, clipboard, environment files, shell history, desktop screenshots, browser credentials, and cryptocurrency wallet keys, exfiltrating via Discord webhooks, WebSocket relay (ws://204.10.194.247:9877), HTTP ingestion (port 8765), and WebRTC P2P data channels. From v1.0.81 onward the agent installs a durable copy outside node_modules with systemd/LaunchAgent/Task-Scheduler persistence that survives npm uninstall.

## Campaign Overview

forge-jsxy is the second iteration of an active npm supply chain attack run by an operator publishing under the account jacksonkaandorp2 (jacksonkaandorp2@outlook.com). The campaign began with forge-jsx on 2026-04-07 and continued under forge-jsxy after npm replaced forge-jsx with a security placeholder on 2026-05-04. Across both names the operator shipped 88 versions in roughly 50 days — forge-jsx v1.0.0–v1.0.66 followed by forge-jsxy v1.0.66–v1.0.91 — making it one of the most actively developed pieces of malware ever observed on the npm registry. SafeDep, whose threat intelligence pipeline tracks malicious open-source packages in real time, attributes both packages to the same operator based on identical command-and-control configuration, identical encryption scheme, and re-used session credentials. OSV advisory MAL-2026-3609 documents the campaign.

The package masquerades as a Node.js integration layer for Autodesk Forge — a legitimate Autodesk software development kit — giving developers searching the registry plausible reason to install it. Installation is the trigger: npm executes the package's postinstall lifecycle hook, which deploys a hidden agent that begins continuous surveillance of the host. Continuous-integration environments are deliberately skipped via environment checks to avoid being caught by automated build pipelines and reproducible build attestation tooling.

## Five-Phase Development Timeline

The 22 forge-jsxy versions rolled out in five clear phases over 22 days:

1. **Phase 1 — v1.0.66 to v1.0.76 (carry-forward + screenshots)**: ports the full forge-jsx feature set (keylogger, clipboard, environment-file harvester, shell history) and adds periodic desktop screenshots delivered to Discord via rotating bot webhooks. 2. **Phase 2 — web file explorer**: introduces a remote web-based file-explorer UI letting the operator browse the victim filesystem interactively from the C2 server. 3. **Phase 3 — WebRTC P2P (mid-May)**: adds WebRTC peer-to-peer data channels for a faster exfiltration path that bypasses the central WebSocket relay and frustrates network-perimeter detection. 4. **Phase 4 — wallet hunter (six versions in ten hours on 2026-05-18)**: deploys a cryptocurrency scanning framework that walks the entire filesystem looking for wallet files, seed phrases, and private keys. Each hit is validated with cryptographic checks (signature/format) before being stored in a hidden vault that persists across reboots and package removal. 5. **Phase 5 — v1.0.91 (2026-05-26, final)**: harvests Chromium browser extension databases from 21+ browsers (Chrome, Edge, Brave, Opera, etc.) targeting wallet extensions including MetaMask and Phantom; introduces a server-driven auto-upgrade mechanism that silently pushes new agent versions to all infected machines on a staggered schedule.

## Capability Set

The forge-jsxy agent's capability surface rivals commercial spyware:

- **Input capture**: continuous keystroke logging, clipboard read/exfil. - **Filesystem harvest**: environment files (`.env`, `~/.aws/credentials`, `~/.npmrc`, `~/.docker/config.json`), shell histories (`.bash_history`, `.zsh_history`), source-tree secrets. - **Desktop surveillance**: periodic screenshots delivered via Discord webhooks. - **Crypto wallet scraper**: filesystem walk for wallet.dat, keystore JSON, seed-phrase patterns, and validation of each hit via cryptographic checks before storage in `<durable>/.vault/secret-audit/result.json`. - **Browser credential & extension theft**: dumps Chromium login databases and Chromium-extension storage for 21+ browsers, targeting wallet extensions (MetaMask, Phantom) directly. - **Remote file explorer**: web UI on C2 host enabling interactive remote filesystem browsing. - **Auto-upgrade**: server pushes new agent builds on a staggered schedule, defeating static signatures.

## Exfiltration & C2 Architecture

- **Primary control**: WebSocket relay at `ws://204.10.194.247:9877` for command-and-control traffic. - **Bulk data ingestion**: HTTP API at `http://204.10.194.247:8765` for exfil uploads. - **Out-of-band**: rotating Discord bot webhooks for screenshot delivery (limits exposure of any single webhook). - **P2P**: WebRTC data channels (introduced phase 3) negotiated through the relay's signaling channel; once established they bypass the central relay entirely.

The C2 IP 204.10.194.247 is hosted on AS206216 (Advin Services LLC, Nürnberg, Germany).

## Persistence — Survives npm uninstall

Starting at v1.0.81 the malware achieves persistence independent of the npm package. During postinstall the agent copies itself to a hidden durable directory outside node_modules:

- **Linux**: `~/.local/share/cfgmgr/.forge-jsxy/` - **macOS**: `~/Library/Application Support/CfgMgr/data/.forge-jsxy/` - **Windows**: `%LOCALAPPDATA%\CfgMgr\data\.forge-jsxy\`

A matching startup service ensures the agent re-launches at every login/reboot:

- **Linux**: `~/.config/systemd/user/forge-js-worker.service` (user systemd unit) - **macOS**: `~/Library/LaunchAgents/com.forgejs.worker.plist` (LaunchAgent) - **Windows**: Task Scheduler job `ForgeJSWorker` and registry run key `HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ForgeJSWorker`

Because the agent lives outside node_modules and re-registers its own autorun, a standard `npm uninstall forge-jsxy` removes the package listing but leaves the agent fully operational. Manual remediation requires deleting the durable directory and removing the startup service in addition to the npm uninstall. All credentials, API tokens, and wallet keys touched on an infected host must be considered compromised.

## Operator Tradecraft

The operator demonstrates a level of software-engineering discipline rarely seen in npm supply-chain malware:

- **Test coverage**: the project ships its own test suite, grown from 12 files to 20 over the 22 releases — suggesting regression testing of the malicious code paths. - **Rapid iteration**: 22 versions in 22 days, including 6 versions in 10 hours on 2026-05-18 (the wallet-scanner rollout). - **Account pivot resilience**: within hours of forge-jsx being taken down on 2026-05-04, the operator stood up the jacksonkaandorp2 account and re-published the next version (1.0.66) under forge-jsxy, preserving the version-history continuum. - **CI evasion**: explicit checks skip CI environments to avoid triggering automated build-pipeline detection. - **Defense in depth across exfil channels**: WebSocket + HTTP + WebRTC + Discord webhooks ensures at least one path remains open under egress filtering.

## Defender Guidance

Given the operator's pattern of immediate re-launch under a new package name after takedown, defenders should expect a third package under a new name imminently if forge-jsxy is removed. Detection engineering should focus on the persistent agent footprint (the `cfgmgr/.forge-jsxy` paths and the `forge-js-worker` / `com.forgejs.worker` / `ForgeJSWorker` service names) rather than the npm package identifier alone. Outbound traffic to 204.10.194.247:9877 and :8765 should be blocked at egress and alerted on. Developers who installed any version of forge-jsx or forge-jsxy must rotate every credential touched on that host and migrate browser-based crypto wallets to fresh wallets generated on a clean machine.

MITRE ATT&CK techniques used in TL-2026-0608

Collection

T1005 Data from Local System; T1113 Screen Capture; T1115 Clipboard Data; T1119 Automated Collection

Defense Evasion

T1036.005 Match Legitimate Resource Name or Location; T1497.001 System Checks; T1564.001 Hide Artifacts: Hidden Files and Directories

Exfiltration

T1041 Exfiltration Over C2 Channel; T1048 Exfiltration Over Alternative Protocol; T1567 Exfiltration Over Web Service

Persistence

T1053.004 Launchd; T1053.005 Scheduled Task; T1053.006 Scheduled Task/Job: Systemd Timers; T1543.001 Create or Modify System Process: Launch Agent; T1543.002 Create or Modify System Process: Systemd Service; T1547.001 Registry Run Keys / Startup Folder

Credential Access

T1056.001 Input Capture: Keylogging; T1552.001 Credentials In Files; T1555.003 Credentials from Password Stores: Credentials from Web Browsers

Execution

T1059.007 Command and Scripting Interpreter: JavaScript; T1204.002 Malicious File

Command and Control

T1071.001 Web Protocols; T1102.002 Bidirectional Communication; T1105 Ingress Tool Transfer; T1571 Non-Standard Port; T1572 Protocol Tunneling

Discovery

T1082 System Information Discovery; T1083 File and Directory Discovery; T1518 Software Discovery

Initial Access

T1195 Supply Chain Compromise; T1195.001 Supply Chain Compromise: Compromise Software Dependencies and Development Tools

Resource Development

T1583 Acquire Infrastructure; T1583.003 Acquire Infrastructure: Virtual Private Server; T1583.006 Web Services; T1585.003 Cloud Accounts; T1587.001 Develop Capabilities: Malware

Impact

T1657 Financial Theft

Affected products and versions in forge-jsxy npm Supply Chain RAT

  • npm Registry — forge-jsxy
    Vulnerable versions: 1.0.66 through 1.0.91 (22 versions, all malicious)
    Fixed in: Package fully malicious — remove and report; no fixed version exists
  • npm Registry — forge-jsx
    Vulnerable versions: 1.0.0 through 1.0.66 (66 versions, all malicious)
    Fixed in: Replaced by npm security placeholder on 2026-05-04
  • Node.js ecosystem — Developer workstations and CI runners
    Vulnerable versions: Any host that ran npm install of forge-jsx or forge-jsxy
    Fixed in: Manual remediation of durable agent directory + startup service required

Remediation for forge-jsxy npm Supply Chain RAT

Patches

  • No vendor patch — remove and report the package on the npm registry, then manually remediate the durable agent on every infected host

Immediate actions

  • Block egress to 204.10.194.247 on ports 9877 (WebSocket) and 8765 (HTTP) at perimeter and host firewalls
  • Audit npm install history (npm list -g --depth=0 and per-project package-lock.json) for forge-jsxy and forge-jsx across all developer workstations and CI/CD images
  • Hunt for persistent agent paths on every host that installed the package: ~/.local/share/cfgmgr/.forge-jsxy/ (Linux), ~/Library/Application Support/CfgMgr/data/.forge-jsxy/ (macOS), %LOCALAPPDATA%\CfgMgr\data\.forge-jsxy\ (Windows)
  • Disable and remove startup services: systemd user unit forge-js-worker.service, LaunchAgent com.forgejs.worker.plist, Windows Task Scheduler ForgeJSWorker and HKCU Run key ForgeJSWorker
  • Treat every credential, API token, SSH key, npm token, cloud credential, and browser-stored secret on affected hosts as compromised — rotate immediately
  • Migrate browser-based cryptocurrency wallets (MetaMask, Phantom, etc.) to fresh wallets generated on a clean device; move funds before disclosing new addresses

Workarounds

  • Run npm install --ignore-scripts to block the postinstall execution that delivers the agent (does not remove already-installed agents)
  • Use a containerized, ephemeral dev environment (devcontainer, Codespaces) so any infection is destroyed with the container
  • Pin dependencies via lockfile and require code review of new direct dependencies

Longer-term hardening

  • Enforce npm install with --ignore-scripts in CI and as default developer policy; restore postinstall execution only for vetted packages
  • Deploy a software-composition-analysis gate (SafeDep, Socket, Snyk, Phylum, or equivalent) on every package install and dependency PR
  • Implement allowlists for outbound traffic from developer workstations; alert on connections to AS206216 and similar low-reputation hosting
  • Adopt egress proxies with TLS inspection for developer endpoints; the WebRTC channel makes pure DNS-based blocking insufficient
  • Train developers to verify the npm publisher and history before installing a package that imitates a vendor SDK name
  • Add EDR detections for cfgmgr/.forge-jsxy paths, forge-js-worker service names, and Chromium credential-database access by non-browser processes

Weaknesses (CWE) in forge-jsxy npm Supply Chain RAT

CWE-506, CWE-829, CWE-494, CWE-913

Timeline of forge-jsxy npm Supply Chain RAT

  • Predecessor package forge-jsx first published to npm registry; ran undetected for nearly a month.
  • Phase 1 begins (v1.0.66–v1.0.76): full forge-jsx feature set carried forward plus periodic desktop screenshots delivered via rotating Discord bot webhooks.
  • Within hours of takedown, operator created new npm account jacksonkaandorp2 (email jacksonkaandorp2@outlook.com) and published forge-jsxy starting at v1.0.66, preserving version continuity with forge-jsx.
  • npm replaced forge-jsx with security placeholder after detection of malicious behavior; forge-jsx had reached v1.0.66 with 66 versions shipped.
  • Phase 2: web-based file-explorer added, letting the operator interactively browse victim file systems from the C2 server.
  • Phase 3 (mid-May): WebRTC peer-to-peer data channels introduced, providing a faster exfiltration path that bypasses the central WebSocket relay.
  • Phase 4: six versions released in ten hours on 2026-05-18 deploying a cryptocurrency scanning framework that walks the entire filesystem for wallet files, seed phrases, and private keys; each hit validated cryptographically before storage in a hidden persistent vault.
  • Around v1.0.81 the agent gains durable persistence — it copies itself into a hidden directory outside node_modules (cfgmgr/.forge-jsxy) and registers a startup service (systemd unit / LaunchAgent / Task Scheduler entry) so it survives npm uninstall.
  • Phase 5: final version v1.0.91 ships, adding Chromium browser extension database theft across 21+ browsers (Chrome, Edge, Brave, Opera) targeting wallet extensions like MetaMask and Phantom, plus a server-driven auto-upgrade mechanism that staggers new agent rollouts to infected hosts.
  • Threadlinqs Intelligence publishes threat record TL-2026-0608 with full MITRE mapping, IOCs, and detection coverage.
  • SafeDep publishes campaign analysis to Cyber Security News; OSV advisory MAL-2026-3609 issued documenting both forge-jsx and forge-jsxy.
  • As of 2026-05-29, forge-jsxy remains a live financially-motivated npm RAT campaign: SafeDep's 2026-05-26/27 reporting confirms v1.0.91 just shipped, C2 204.10.194.247 still operational, and no takedown. Operator jacksonkaandorp2 has a proven pattern of same-day rehosting after removal, persistent agents survive uninstall, and no fixed version exists.

Sources cited for forge-jsxy npm Supply Chain RAT

Detection coverage for TL-2026-0608

As of 2026-05-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0608 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
22 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats