MicrosoftSystem64 is a cross-platform Node.js-based remote-access trojan and infostealer distributed through malicious npm packages, including typosquatted dependencies and packages that execute malware through installation lifecycle hooks. It targets Windows, macOS, and Linux systems, establishes user-level persistence using native platform mechanisms, and communicates with operator infrastructure over WebSocket and HTTP. The implant performs host and filesystem discovery; supports arbitrary file operations, command execution, deployment of additional binaries, self-updating, and removal; and can reconnect and resume interrupted activity. It collects browser credentials and session data, cryptocurrency-wallet extension data, Telegram Desktop data, SSH keys, cloud and developer credentials, shell history, clipboard contents, screenshots, and keystrokes. Stolen material can be archived and exfiltrated through attacker-controlled private Hugging Face datasets. MicrosoftSystem64 incorporates anti-analysis checks that avoid execution on low-processor systems. Campaign activity has been linked with moderate-to-strong circumstantial evidence to the DPRK-associated FAMOUS CHOLLIMA, also known as Contagious Interview, cluster. Developers, cryptocurrency users, and trading-tool users are prominent targets due to the use of open-source package and repository lures.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Le payload s’installe en persistance sous le nom MicrosoftSystem64 sur Windows, macOS et Linux, établit une connexion WebSocket vers un serveur de commande et expose les commandes ping, get_system_info, list_drives, list_dir, deploy_binary et remove_agent.
"Inside MicrosoftSystem64: A Supply Chain RAT Exfiltrating to HuggingFace" published by SafeDep.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
MicrosoftSystem64 , a multi-platform Node.js-SEA RAT/infostealer delivered through the npm js-logger-pack family of 29 versions in Apr 2026 and the May 2026 successor packages terminal-logger-utils , ts-logger-pack , pretty-logger-utils , and pinno-loggers .
The trigger is the postinstall script in the 2.12.x releases: "postinstall": "node -e ... && node dist/node/utils.js".
Windows : tâche planifiée \MicrosoftSystem64 + MicrosoftSystem64.vbs.
Expected observations: node.exe spawning powershell.exe with -NoProfile and -ExecutionPolicy Bypass ... PowerShell script content containing Add-Type and C# source code
The trigger is the postinstall script in the 2.12.x releases: "postinstall": "node -e ... && node dist/node/utils.js".
Windows : tâche planifiée \MicrosoftSystem64 + MicrosoftSystem64.vbs.
The trigger is the postinstall script in the 2.12.x releases: "postinstall": "node -e ... && node dist/node/utils.js".
Windows : tâche planifiée \MicrosoftSystem64 + MicrosoftSystem64.vbs.
Le payload décode une configuration obfusquée (XOR + Base64).
The embedded Windows keylogger source also contained password-context classification logic ... captured keystrokes were not just raw input. They were labeled with likely sensitivity before being sent back to the operator.
Depending on what is present, the exposed material may include ... Docker registry tokens npm or PyPI publishing tokens ... exchange API keys ... Response should include rotation or revocation of ... npm tokens PyPI tokens ... API keys
Depending on what is present, the exposed material may include ... SSH keys ... Response should include rotation or revocation of: SSH keys
The collection targets matched the lure audience ... Shell history targets included ... Developer credential targets included ... Wallet and browser-extension targets included ... Telegram Desktop collection targeted: Telegram Desktop/tdata
The embedded Windows keylogger source also contained password-context classification logic ... captured keystrokes were not just raw input. They were labeled with likely sensitivity before being sent back to the operator.
After resolving the string map, capability and infrastructure strings were recoverable, including: take_screenshot ... Screenshot Capture From Non-Interactive Node-Controlled Helpers Hypothesis ... attackers may use OS-native screenshot mechanisms through helper processes controlled by the Node.js agent
52 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote-access payload delivered through the malicious npm dependency chain. It establishes WebSocket C2 communications, persists across Windows, macOS, and Linux, performs host and filesystem discovery, and can deploy a second-stage binary. Its launcher avoids systems with fewer than four processors, likely to evade analysis environments.
Cross-platform Node.js-based remote-access implant delivered via malicious npm-package dependency chaining. Its first-stage agent performs host reconnaissance, filesystem enumeration, command-and-control beaconing, persistence, and deployment/execution of operator-provided binaries. An earlier MicrosoftSystem64 implant was reported to steal browser credentials, cryptocurrency-wallet data, Telegram sessions, and SSH keys.
A persistent Node.js-based malware family delivered via malicious GitHub/npm trading-bot lures. It copies a payload to user-writable paths under the MicrosoftSystem64 name, establishes user-level persistence across Windows/macOS/Linux, and steals developer and crypto-related data including shell history, cloud and package-manager credentials, SSH keys, wallet files/extension state, Telegram Desktop data, screenshots, files, clipboard contents, and keystrokes. It also supports command execution, file operations, SSH collection, and exfiltration via HuggingFace with WebSocket-based tasking.
Cross-platform remote access trojan delivered via poisoned npm packages that steals browser credentials, cryptocurrency wallet data, Telegram Desktop sessions, SSH keys, keystrokes, and screenshots; persists across Windows, Linux, and macOS; uses HuggingFace for binary hosting, self-updates, and exfiltration; and supports remote command execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.