forge-jsxy@1.0.91
Malicious code in forge-jsxy (npm)
T1059 · Command and Scripting InterpreterT1546.016 · Installer Packages
Analysis
On installation, the package spawns a detached background process that establishes OS-level autostart persistence and exposes remote-control capabilities. The agent integrates with Discord and Hugging Face endpoints and monitors the system clipboard, giving an operator persistent remote access and the ability to harvest clipboard contents.
- analyzed by
- Leitwacht
- first seen
- May 26, 2026, 03:34 PM
- analyzed
- May 26, 2026, 06:33 PM
- weekly installs
- 1,318
Related advisories
- eslint-plugin-vitest-ts@1.0.4
- fundraiserserv@28.0.0
- relativity-pdfjs-dist@99.9.9
- client-cookies-agent@99.9.7
- @wagni_bot/pumpfun-sdk@1.2.0
- @wagni_bot/solana-sdk@1.2.0
- @playerdata-internal/playerdata-core@9999.99.20
- vps-maintenance-paperclip-adapter@0.1.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.