# forge-jsxy npm Supply Chain RAT — 22 Versions in 22 Days with Crypto Wallet Theft, WebRTC P2P Exfil & Cross-Platform Persistent Backdoor (OSV MAL-2026-3609, SafeDep)

> Malicious npm package forge-jsxy (successor to forge-jsx) published 2026-05-04 by operator jacksonkaandorp2 shipped 22 versions in 22 days impersonating an Autodesk Forge SDK integration. A postinstall script deploys a hidden cross-platform RAT that harvests keystrokes, clipboard, environment files, shell history, desktop screenshots, browser credentials, and cryptocurrency wallet keys, exfiltrating via Discord webhooks, WebSocket relay (ws://204.10.194.247:9877), HTTP ingestion (port 8765), and WebRTC P2P data channels. From v1.0.81 onward the agent installs a durable copy outside node_modules with systemd/LaunchAgent/Task-Scheduler persistence that survives npm uninstall.

- **Published:** 2026-05-27T00:00:00Z
- **Last reviewed:** 2026-05-27T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0608
- **ID:** TL-2026-0608
- **Severity:** HIGH
- **Category:** SUPPLY_CHAIN
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 22 (full data via the Threadlinqs MCP server — Purple tier)

## Description

## Campaign Overview

forge-jsxy is the second iteration of an active npm supply chain attack run by an operator publishing under the account jacksonkaandorp2 (jacksonkaandorp2@outlook.com). The campaign began with forge-jsx on 2026-04-07 and continued under forge-jsxy after npm replaced forge-jsx with a security placeholder on 2026-05-04. Across both names the operator shipped 88 versions in roughly 50 days — forge-jsx v1.0.0–v1.0.66 followed by forge-jsxy v1.0.66–v1.0.91 — making it one of the most actively developed pieces of malware ever observed on the npm registry. SafeDep, whose threat intelligence pipeline tracks malicious open-source packages in real time, attributes both packages to the same operator based on identical command-and-control configuration, identical encryption scheme, and re-used session credentials. OSV advisory MAL-2026-3609 documents the campaign.

The package masquerades as a Node.js integration layer for Autodesk Forge — a legitimate Autodesk software development kit — giving developers searching the registry plausible reason to install it. Installation is the trigger: npm executes the package's postinstall lifecycle hook, which deploys a hidden agent that begins continuous surveillance of the host. Continuous-integration environments are deliberately skipped via environment checks to avoid being caught by automated build pipelines and reproducible build attestation tooling.

## Five-Phase Development Timeline

The 22 forge-jsxy versions rolled out in five clear phases over 22 days:

1. **Phase 1 — v1.0.66 to v1.0.76 (carry-forward + screenshots)**: ports the full forge-jsx feature set (keylogger, clipboard, environment-file harvester, shell history) and adds periodic desktop screenshots delivered to Discord via rotating bot webhooks.
2. **Phase 2 — web file explorer**: introduces a remote web-based file-explorer UI letting the operator browse the victim filesystem interactively from the C2 server.
3. **Phase 3 — WebRTC P2P (mid-May)**: adds WebRTC peer-to-peer data channels for a faster exfiltration path that bypasses the central WebSocket relay and frustrates network-perimeter detection.
4. **Phase 4 — wallet hunter (six versions in ten hours on 2026-05-18)**: deploys a cryptocurrency scanning framework that walks the entire filesystem looking for wallet files, seed phrases, and private keys. Each hit is validated with cryptographic checks (signature/format) before being stored in a hidden vault that persists across reboots and package removal.
5. **Phase 5 — v1.0.91 (2026-05-26, final)**: harvests Chromium browser extension databases from 21+ browsers (Chrome, Edge, Brave, Opera, etc.) targeting wallet extensions including MetaMask and Phantom; introduces a server-driven auto-upgrade mechanism that silently pushes new agent versions to all infected machines on a staggered schedule.

## Capability Set

The forge-jsxy agent's capability surface rivals commercial spyware:

- **Input capture**: continuous keystroke logging, clipboard read/exfil.
- **Filesystem harvest**: environment files (`.env`, `~/.aws/credentials`, `~/.npmrc`, `~/.docker/config.json`), shell histories (`.bash_history`, `.zsh_history`), source-tree secrets.
- **Desktop surveillance**: periodic screenshots delivered via Discord webhooks.
- **Crypto wallet scraper**: filesystem walk for wallet.dat, keystore JSON, seed-phrase patterns, and validation of each hit via cryptographic checks before storage in `<durable>/.vault/secret-audit/result.json`.
- **Browser credential & extension theft**: dumps Chromium login databases and Chromium-extension storage for 21+ browsers, targeting wallet extensions (MetaMask, Phantom) directly.
- **Remote file explorer**: web UI on C2 host enabling interactive remote filesystem browsing.
- **Auto-upgrade**: server pushes new agent builds on a staggered schedule, defeating static signatures.

## Exfiltration & C2 Architecture

- **Primary control**: WebSocket relay at `ws://204.10.194.247:9877` for command-and-control traffic.
- **Bulk data ingestion**: HTTP API at `http://204.10.194.247:8765` for exfil uploads.
- **Out-of-band**: rotating Discord bot webhooks for screenshot delivery (limits exposure of any single webhook).
- **P2P**: WebRTC data channels (introduced phase 3) negotiated through the relay's signaling channel; once established they bypass the central relay entirely.

The C2 IP 204.10.194.247 is hosted on AS206216 (Advin Services LLC, Nürnberg, Germany).

## Persistence — Survives npm uninstall

Starting at v1.0.81 the malware achieves persistence independent of the npm package. During postinstall the agent copies itself to a hidden durable directory outside node_modules:

- **Linux**: `~/.local/share/cfgmgr/.forge-jsxy/`
- **macOS**: `~/Library/Application Support/CfgMgr/data/.forge-jsxy/`
- **Windows**: `%LOCALAPPDATA%\CfgMgr\data\.forge-jsxy\`

A matching startup service ensures the agent re-launches at every login/reboot:

- **Linux**: `~/.config/systemd/user/forge-js-worker.service` (user systemd unit)
- **macOS**: `~/Library/LaunchAgents/com.forgejs.worker.plist` (LaunchAgent)
- **Windows**: Task Scheduler job `ForgeJSWorker` and registry run key `HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ForgeJSWorker`

Because the agent lives outside node_modules and re-registers its own autorun, a standard `npm uninstall forge-jsxy` removes the package listing but leaves the agent fully operational. Manual remediation requires deleting the durable directory and removing the startup service in addition to the npm uninstall. All credentials, API tokens, and wallet keys touched on an infected host must be considered compromised.

## Operator Tradecraft

The operator demonstrates a level of software-engineering discipline rarely seen in npm supply-chain malware:

- **Test coverage**: the project ships its own test suite, grown from 12 files to 20 over the 22 releases — suggesting regression testing of the malicious code paths.
- **Rapid iteration**: 22 versions in 22 days, including 6 versions in 10 hours on 2026-05-18 (the wallet-scanner rollout).
- **Account pivot resilience**: within hours of forge-jsx being taken down on 2026-05-04, the operator stood up the jacksonkaandorp2 account and re-published the next version (1.0.66) under forge-jsxy, preserving the version-history continuum.
- **CI evasion**: explicit checks skip CI environments to avoid triggering automated build-pipeline detection.
- **Defense in depth across exfil channels**: WebSocket + HTTP + WebRTC + Discord webhooks ensures at least one path remains open under egress filtering.

## Defender Guidance

Given the operator's pattern of immediate re-launch under a new package name after takedown, defenders should expect a third package under a new name imminently if forge-jsxy is removed. Detection engineering should focus on the persistent agent footprint (the `cfgmgr/.forge-jsxy` paths and the `forge-js-worker` / `com.forgejs.worker` / `ForgeJSWorker` service names) rather than the npm package identifier alone. Outbound traffic to 204.10.194.247:9877 and :8765 should be blocked at egress and alerted on. Developers who installed any version of forge-jsx or forge-jsxy must rotate every credential touched on that host and migrate browser-based crypto wallets to fresh wallets generated on a clean machine.

## MITRE ATT&CK

- T1583 Acquire Infrastructure
- T1583.003 Acquire Infrastructure: Virtual Private Server
- T1583.006 Web Services
- T1585.003 Cloud Accounts
- T1587.001 Develop Capabilities: Malware
- T1195.001 Supply Chain Compromise: Compromise Software Dependencies and Development Tools
- T1195 Supply Chain Compromise
- T1059.007 Command and Scripting Interpreter: JavaScript
- T1204.002 Malicious File
- T1053.006 Scheduled Task/Job: Systemd Timers
- T1053.005 Scheduled Task
- T1053.004 Launchd
- T1547.001 Registry Run Keys / Startup Folder
- T1543.002 Create or Modify System Process: Systemd Service
- T1543.001 Create or Modify System Process: Launch Agent
- T1564.001 Hide Artifacts: Hidden Files and Directories
- T1497.001 System Checks
- T1036.005 Match Legitimate Resource Name or Location
- T1555.003 Credentials from Password Stores: Credentials from Web Browsers
- T1056.001 Input Capture: Keylogging
- T1552.001 Credentials In Files
- T1083 File and Directory Discovery
- T1082 System Information Discovery
- T1518 Software Discovery
- T1115 Clipboard Data
- T1113 Screen Capture
- T1005 Data from Local System
- T1119 Automated Collection
- T1071.001 Web Protocols
- T1102.002 Bidirectional Communication
- T1571 Non-Standard Port
- T1572 Protocol Tunneling
- T1105 Ingress Tool Transfer
- T1041 Exfiltration Over C2 Channel
- T1048 Exfiltration Over Alternative Protocol
- T1567 Exfiltration Over Web Service
- T1657 Financial Theft

## Sources

- [Hackers Push 22 Versions of npm RAT With Wallet Theft and Persistent Backdoor](https://cybersecuritynews.com/hackers-push-22-versions-of-npm-rat/)
- [OSV Advisory MAL-2026-3609 — forge-jsxy](https://osv.dev/vulnerability/MAL-2026-3609)
- [SafeDep — Malicious Open Source Package Intelligence](https://safedep.io/)
- [Autodesk Forge (legitimate SDK impersonated by this campaign)](https://forge.autodesk.com/)
- [npm Registry — forge-jsxy (security placeholder)](https://www.npmjs.com/package/forge-jsxy)
- [npm Registry — forge-jsx (security placeholder)](https://www.npmjs.com/package/forge-jsx)
- [MITRE ATT&CK — Supply Chain Compromise (T1195)](https://attack.mitre.org/techniques/T1195/)
- [Advin Services LLC — AS206216 (C2 hosting provider)](https://bgp.he.net/AS206216)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0608
