A Supply Chain Rat Exfiltrating to HuggingFace
Researchers at SafeDep discovered a malicious npm package named "microsoftsystem64" that exfiltrates credentials and system info to HuggingFace. The package uses a known SSRF vulnerability to steal cloud metadata from cloud environments, posing a significant supply chain risk.