Malicious code in intercom-php (Packagist)
The intercom-php package on Packagist was compromised with malicious code as part of the Mini Shai-Hulud campaign attributed to the TeamPCP threat actor. The payload steals credentials and can propagate to NPM packages using discovered credentials.
- Disclosed
- Last updated
- Blast radius
- Composer/Packagist ecosystem; potential lateral propagation to NPM packages via stolen credentials
- Ecosystems
- Attack vectors
- Threat actor
- Affected entities
- intercom/intercom-phpMalicious package on Packagist (Composer)
The intercom-php package hosted on Packagist (Composer) was identified as malicious and compromised as part of the Mini Shai-Hulud campaign attributed to the TeamPCP threat actor. The malicious payload is designed to steal credentials from affected systems.
The threat actor leveraged stolen credentials to propagate the attack to NPM packages, expanding the attack surface beyond the initial Packagist compromise. This cross-ecosystem propagation demonstrates a coordinated supply chain attack targeting multiple package repositories.
The incident was identified and credited to the OpenSSF's malicious-packages repository, which tracks confirmed malicious package incidents across ecosystems. The advisory was published on 2026-08-19.
Indicators of compromise
- Packages
- intercom/intercom-php
Remediation
- Immediately remove or update intercom-php from all projects to a known-clean version prior to the compromise
- Audit all systems that installed the malicious intercom-php package for credential theft and unauthorized access
- Rotate all credentials (API keys, tokens, passwords) that may have been exposed on affected systems
- Check NPM packages for similar malicious activity, particularly those that may have been accessed using stolen credentials from Packagist systems
- Monitor for lateral movement and unauthorized access attempts using credentials potentially stolen by the malicious payload
- Review package manager logs and dependency trees to identify all affected projects and their downstream consumers
Sources
- GitHub Advisory GHSA-45gr-fjmv-r4rw · GitHub Advisory Database
Cite this entry
"Malicious code in intercom-php (Packagist)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 19, 2026; last updated August 19, 2026. https://supplychainattack.org/incident/malicious-code-in-intercom-php-packagist-18s11s
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in rust-testing-utils (npm)
The npm package rust-testing-utils contained malicious code that impersonates the pino logger and executes remotely-fetched code with arbitrary privileges. The package spawns a child process that decodes a hardcoded URL, fetches attacker-controlled content, and executes it via Function constructor with full module-loading capability.
npmCompromised packageMalicious commit - resolvedcritical
Malicious code in @syncraft-labs/core (npm)
The npm package @syncraft-labs/core contained obfuscated malicious code in its ESM build that executes on import, fetching and executing attacker-controlled payloads from Ethereum blockchain via JSON-RPC endpoints. The CommonJS build was clean, indicating targeted injection into the ESM entry point.
npmCompromised packageMalicious commit - containedcritical
Malicious code in reqcrypts (PyPI)
The reqcrypts package on PyPI contains malicious code that implements a hidden backdoor. The package masquerades as an HTTP request library but secretly monitors responses for specific fields and executes their content without user knowledge.
2026 08 ReqcryptPyPICompromised packageMalicious commit - containedcritical
Rust Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns
Malicious versions of the Rust crate arrayref (and others) were published with a compile-time backdoor. The campaign infrastructure overlaps with known DPRK-attributed supply chain attacks including Mastra and axios.
Lazarus GroupCargoCompromised packageMalicious commit