malware
npm
@johntaohunter/forge-jsx
discovered 2026-04-15@johntaohunter/forge-jsx is identified in the SafeDep analysis "forge-jsx npm Package: Purpose-Built Multi-Platform RAT". forge-jsx poses as an Autodesk Forge SDK on npm. On install it deploys a system-wide keylogger, recursive .env file scanner, shell history exfiltrator, and a WebSocket-based remote filesystem backdoor to C2 at 204.10.194.247, with persistence via systemd, LaunchAgent, and Task Scheduler.
Threat types
rat credential_stealer data_exfiltration persistence c2_agent
Malicious versions
- 1.0.4