Inside MicrosoftSystem64: A Supply Chain RAT Exfiltrating to HuggingFace
2026-05-28 • Safe Dep •
https://safedep.io/microsoftsystem64-binary-payload-analysis/
A malicious npm package, js-logger-pack, evolved from a probe into a dropper for MicrosoftSystem64, a cross-platform Node.js Single Executable Application that functions as an infostealer and RAT. The payload targets browser credentials, more than 80 cryptocurrency wallet extensions, Telegram Desktop sessions, SSH keys, clipboard data, keystrokes, and screenshots across Linux, Windows, and macOS. It connects to a WebSocket C2 at 195.201.194.107:8010, accepts 24 remote task types including shell execution and file theft, and exfiltrates data to attacker-controlled HuggingFace datasets using an embedded token. SafeDep found the infrastructure still active on May 28, with valid HuggingFace credentials, accepting C2 connectivity, and real victims under active surveillance, showing that public disclosure had not immediately disrupted the operation.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | http://195.201.194.107:8010 | 2026-05-29 | 2026-05-29 |
| IPv4 | 195.201.194.107 | 2025-04-15 | 2026-05-29 |
| DOMAIN | changelog.rest | 2026-05-28 | 2026-05-28 |
| DOMAIN | sha256-validate-rpc.vercel.app | 2026-05-28 | 2026-05-28 |
| DOMAIN | copilot-ai.whisdev.org | 2026-05-28 | 2026-05-28 |
| URL | http://195.201.194.107:8010/api… | 2026-05-28 | 2026-05-28 |
| URL | https://huggingface.co/jpeek998… | 2026-05-28 | 2026-05-28 |
| HASH | d4a81c2dd56e685af3f8cf5428a0f47b | 2026-05-28 | 2026-05-28 |