Researchers reported that the MicrosoftSystem64 remote access trojan is being delivered through poisoned npm packages including js-logger-pack, expanding from a software supply chain lure into a full second-stage malware deployment aimed at developers. SafeDep first documented the payload and JFrog later independently confirmed the activity, while public reporting and threat-tracking posts linked the campaign to the North Korea-associated Contagious Interview / Famous Chollima cluster. The malware is described as cross-platform, with persistence mechanisms for Windows, macOS, and Linux, and remained active with attacker infrastructure and victim monitoring still online.
The RAT steals browser credentials, cryptocurrency wallet data, Telegram Desktop sessions, SSH keys, keystrokes, and screenshots, then uses private HuggingFace datasets for payload hosting and data exfiltration. Researchers said this abuse of HuggingFace helps the traffic blend into legitimate HTTPS API activity, making detection more difficult than conventional command-and-control channels. The campaign highlights a growing tactic in which trusted developer ecosystems and mainstream cloud platforms are combined to hide malware delivery and stolen-data transfers.

Trace attribution and downstream blast radius.
6 events from the most recent confirmed update back to the earliest known activity.
SecurityOnline reported that researchers had identified SolyxImmortal as a Python-based Windows info stealer that harvests credentials, files, keystrokes, and screenshots, establishes persistence in APPDATA and the Run key, and exfiltrates stolen data through Discord webhooks.
Researchers reported on MicrosoftSystem64 as a cross-platform RAT delivered through malicious npm packages that steals credentials, wallet data, SSH keys, screenshots, and other information while using private HuggingFace datasets for stealthy exfiltration.
A Bluesky post by lazarusholic shared SafeDep's report on MicrosoftSystem64 and associated the activity with DPRK-linked software supply chain intrusion tags including #FamousChollima and #DPRK.
Researchers reported that the MicrosoftSystem64 operation was still active as of May 28, 2026, with attacker infrastructure online and live victim monitoring continuing. The campaign was attributed to the North Korea-linked Contagious Interview threat group.
Pulsedive published an analysis of SolyxImmortal, describing a Python-based Windows information stealer that persists via a Run key, steals browser data and documents, logs keystrokes, captures screenshots, and reportedly exfiltrates data through Discord webhooks. The report also noted Turkish-language strings and targeting indicators in the malware.
SafeDep first documented the second-stage payload of the MicrosoftSystem64 campaign, which used malicious npm packages and private HuggingFace datasets for payload hosting and data exfiltration.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
4 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecybersecuritynews.com
Open sourcebsky.app
Open sourceblog.pulsedive.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.