Inside MicrosoftSystem64: A Supply Chain RAT Exfiltrating to HuggingFace

2026-05-28 Safe Dep

https://safedep.io/microsoftsystem64-binary-payload-analysis/

Thumbnail for Inside MicrosoftSystem64: A Supply Chain RAT Exfiltrating to HuggingFace

A malicious npm package, js-logger-pack, evolved from a probe into a dropper for MicrosoftSystem64, a cross-platform Node.js Single Executable Application that functions as an infostealer and RAT. The payload targets browser credentials, more than 80 cryptocurrency wallet extensions, Telegram Desktop sessions, SSH keys, clipboard data, keystrokes, and screenshots across Linux, Windows, and macOS. It connects to a WebSocket C2 at 195.201.194.107:8010, accepts 24 remote task types including shell execution and file theft, and exfiltrates data to attacker-controlled HuggingFace datasets using an embedded token. SafeDep found the infrastructure still active on May 28, with valid HuggingFace credentials, accepting C2 connectivity, and real victims under active surveillance, showing that public disclosure had not immediately disrupted the operation.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://195.201.194.107:8010 2026-05-29 2026-05-29
IPv4 195.201.194.107 2025-04-15 2026-05-29
DOMAIN changelog.rest 2026-05-28 2026-05-28
DOMAIN sha256-validate-rpc.vercel.app 2026-05-28 2026-05-28
DOMAIN copilot-ai.whisdev.org 2026-05-28 2026-05-28
URL http://195.201.194.107:8010/api… 2026-05-28 2026-05-28
URL https://huggingface.co/jpeek998… 2026-05-28 2026-05-28
HASH d4a81c2dd56e685af3f8cf5428a0f47b 2026-05-28 2026-05-28

Related Actors

Related Reports

« Back