Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access
2026-06-28T02:52:19Z•9a979f1f01fabf66e19bac59b5cb2e59603479e7157434fc8798fa21b1343a60
ai-agent-rceamadeyasiaautogen-studioautojackcrypto-clippereuropehospitality-sectorinfostealermalspammastramcp-websocketnodejs-implantnpm-supply-chainpersistencephoto-zipsapphire-sleetshortcut-lnkstealctorworm-propagation
What happened
Microsoft Threat Intelligence reported multiple active campaigns and research covering supply-chain and host-targeting risks. Key incidents: a Photo ZIP campaign targeting hospitality organizations in Europe and Asia that uses photo-themed ZIPs and fake image shortcut files to deliver a persistent Node.js implant; a technical breakdown and takedown activity against StealC and Amadey infostealer infrastructures; the Mastra npm supply-chain compromise (Sapphire Sleet) that delivered a postinstall payload to 140+ projects; AutoJack research showing how a malicious webpage can achieve host RCE by欺
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 9a979f1f01fabf66e19bac59b5cb2e59603479e7157434fc8798fa21b1343a60
- Enrichment time
- 2026-06-28T02:52:19Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.