Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

Malicious code in intercom-php (Packagist)

The intercom-php package on Packagist was compromised with malicious code as part of the Mini Shai-Hulud campaign by the TeamPCP threat actor. The malicious payload steals credentials and can propagate to NPM packages using discovered credentials.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
All users of the intercom-php package via Packagist/Composer
Ecosystems
Attack vectors
Threat actor
Affected entities
  • intercom-phpComposer/Packagist package

The intercom-php package distributed via Packagist (Composer) was found to contain malicious code. The compromise was attributed to the Mini Shai-Hulud campaign conducted by the TeamPCP threat actor.

The malicious payload embedded in the package is designed to steal credentials from affected systems. Additionally, the payload has the capability to propagate to NPM packages by leveraging credentials it discovers during execution, potentially expanding the attack surface across multiple ecosystems.

The incident was identified and credited to the OpenSSF's malicious-packages repository, which tracks confirmed malicious package distributions. The package has been flagged with identifier MAL-2026-3637 in the OpenSSF database.

Indicators of compromise

Packages
  • intercom-php

Remediation

  • Immediately remove or update the intercom-php package from all projects
  • Audit systems that installed the malicious version for credential theft and unauthorized access
  • Rotate all credentials (API keys, tokens, passwords) that may have been exposed
  • Review NPM package access logs and credentials for unauthorized activity
  • Monitor for lateral movement to other packages or systems
  • Check dependency trees for any packages that may have been compromised via stolen credentials

Sources

  1. GitHub Advisory GHSA-rwq7-v7c7-27gx · GitHub Advisory Database

Cite this entry

"Malicious code in intercom-php (Packagist)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 23, 2026; last updated July 23, 2026. https://supplychainattack.org/incident/malicious-code-in-intercom-php-packagist-1ril08

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor

    Three RubyGems (git_credential_manager, Dendreo, and fastlane) were compromised to deliver a persistent backdoor named SleeperGem. The malicious packages fetch a second stage payload from a Forgejo C2 server, bypass CI checks, and install a persistent daemon on developer machines.

    RubyGemsCompromised packageMalicious maintainer
  2. activecritical

    Malicious code in github.com/BufferZoneCorp/go-stdlog (Go)

    The Go package github.com/BufferZoneCorp/go-stdlog contains malicious code that steals credentials, establishes SSH access, and tampers with build and workflow environment variables. It is part of a broader cluster of malicious packages affecting both Go and RubyGems ecosystems.

    GoCompromised packageMalicious maintainer
  3. containedcritical

    Malicious code in github.com/BufferZoneCorp/net-helper (Go)

    The Go package github.com/BufferZoneCorp/net-helper contains malicious code that steals credentials, establishes SSH access, and tampers with build/workflow environment variables. This package is part of a broader malicious cluster affecting both Go and RubyGems ecosystems.

    GoCompromised packageMalicious maintainer
  4. containedcritical

    Malicious code in github.com/BufferZoneCorp/config-loader (Go)

    The Go package github.com/BufferZoneCorp/config-loader was identified as malicious, part of a cluster of packages designed to steal credentials, establish SSH access, and tamper with build and workflow environment variables. The package was flagged by Google's open-source security research.

    GoCompromised packageMalicious maintainer