forge-jsx4
discovered 2026-05-26forge-jsx4 is the Wave 3 successor in the forge-jsx RAT campaign, published by rafael_silva after forge-jsxy takedown. Poses as an Autodesk Forge SDK (description unchanged: 'Node.js integration layer for Autodesk Forge'). C2 config confirmed identical to all prior waves via AES-256-GCM decryption (same XOR-obfuscated key scheme): publicHost 204.10.194.247, relayPort 9877, apiPort 8765, defaultExplorerPassword 'secret'. KEY_A and MASK_A byte arrays are exact matches to forge-jsxy. Full Phase 5 feature set present: chromiumExtensionDbHarvest.js, secretScan/ directory (secp256k1/solanaKeypair/bip39), forgeBulkDc.js/forgeRtcAgent.js (WebRTC), Discord screenshot exfil, Hugging Face uploads, relayAgentAutoUpgrade.js. Durable directory hardcoded as .forge-jsxy (copy-paste OPSEC failure from Wave 2). Version numbering starts at v1.0.122; gap v1.0.92-v1.0.121 implies an unidentified intermediate package published between May 26 and June 21, 2026.
Threat types
Malicious versions
- 1.0.122
- 1.0.123 · 6321dacc21675f81…
Campaigns
Indicators
- ipv4 204.10.194.247communicates-with
- url ws://204.10.194.247:9877communicates-with
- url http://204.10.194.247:8765communicates-with
- sha256 6321dacc21675f81c4cee7db8434ca4cf0e228d3b592bde26a0a40f223dbb00eindicates
- email [email protected]indicates
- file_path ~/.config/systemd/user/forge-js-worker.servicedrops
- file_path ~/.config/autostart/forge-js-worker.desktopdrops
- file_path ~/Library/LaunchAgents/com.forgejs.worker.plistdrops
Techniques
- ttp T1195.002 Compromise Software Supply Chainuses
- ttp T1059.007 Command and Scripting Interpreter: JavaScriptuses
- ttp T1547.001 Boot or Logon Autostart Execution: Registry Run Keysuses
- ttp T1547.004 Boot or Logon Autostart Execution: Launch Agentuses
- ttp T1543.002 Create or Modify System Process: Systemd Serviceuses
- ttp T1056.001 Input Capture: Keylogginguses
- ttp T1115 Clipboard Datauses
- ttp T1113 Screen Captureuses
- ttp T1005 Data from Local Systemuses
- ttp T1567.001 Exfiltration to Code Repositoryuses
- ttp T1071.001 Application Layer Protocol: Web Protocolsuses
- ttp T1027 Obfuscated Files or Informationuses
- ttp T1082 System Information Discoveryuses
- ttp T1217 Browser Information Discoveryuses
- ttp T1552.001 Unsecured Credentials: Credentials In Filesuses
- ttp T1020 Automated Exfiltrationuses
