Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access

2026-06-28T02:52:19Z9a979f1f01fabf66e19bac59b5cb2e59603479e7157434fc8798fa21b1343a60
ai-agent-rceamadeyasiaautogen-studioautojackcrypto-clippereuropehospitality-sectorinfostealermalspammastramcp-websocketnodejs-implantnpm-supply-chainpersistencephoto-zipsapphire-sleetshortcut-lnkstealctorworm-propagation

What happened

Microsoft Threat Intelligence reported multiple active campaigns and research covering supply-chain and host-targeting risks. Key incidents: a Photo ZIP campaign targeting hospitality organizations in Europe and Asia that uses photo-themed ZIPs and fake image shortcut files to deliver a persistent Node.js implant; a technical breakdown and takedown activity against StealC and Amadey infostealer infrastructures; the Mastra npm supply-chain compromise (Sapphire Sleet) that delivered a postinstall payload to 140+ projects; AutoJack research showing how a malicious webpage can achieve host RCE by欺

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
9a979f1f01fabf66e19bac59b5cb2e59603479e7157434fc8798fa21b1343a60
Enrichment time
2026-06-28T02:52:19Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access · Baitaphish