logo

Hackers Push 22 Versions of npm RAT With Wallet Theft and Persistent Backdoor

ID: 6f2364a2-149a-559e-a566-7eedf832921c

STIX ID: report--6f2364a2-149a-559e-a566-7eedf832921c

Feed Name: cybersecurityNews.com

Threat Score
86/100

Date Published: 2026-05-27

Date Updated: 2026-05-28

Author: Tushar Subhra Dutta

...
...

**Malicious npm supply-chain campaign deploying persistent infostealer:** A malicious npm package (forge-jsxy, successor to forge-jsx) was published and updated rapidly to deploy a cross-platform agent that harvests cryptocurrency wallet keys, browser extensions, credentials, keystrokes, clipboard data, and screenshots, includes persistence that survives npm uninstall, supports remote command-and-control and auto-upgrades, and has documented IoCs for mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.