LWA-2026-0060 MAL-2026-3609 ↗ confirmed malware

forge-jsxy@1.0.91

Malicious code in forge-jsxy (npm)

T1059 · Command and Scripting InterpreterT1546.016 · Installer Packages

Analysis

On installation, the package spawns a detached background process that establishes OS-level autostart persistence and exposes remote-control capabilities. The agent integrates with Discord and Hugging Face endpoints and monitors the system clipboard, giving an operator persistent remote access and the ability to harvest clipboard contents.

analyzed by
Leitwacht
first seen
May 26, 2026, 03:34 PM
analyzed
May 26, 2026, 06:33 PM
weekly installs
1,318

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.