A malicious intercom/intercom-php 5.0.2 package was uploaded to Packagist after an attacker abused compromised publishing rights, turning the legitimate PHP SDK into a Composer plugin that executed malware during install or update. Reports say the package launched setup-intercom.sh, downloaded Bun, and ran an obfuscated router_runtime.js payload tied to the Mini Shai-Hulud campaign, which had previously been linked to a compromised Intercom npm package. Because the payload ran at dependency installation time, affected developer workstations and CI/CD pipelines could be compromised even if the library was never imported by the application.
The malware was described as enabling arbitrary code execution with the privileges of the user running Composer, then harvesting environment variables and credential files from developer, cloud, Kubernetes, Vault, Docker, and application environments. Stolen data was encrypted and exfiltrated to a hardcoded endpoint with a fallback GitHub-based channel, creating risks including unauthorized AWS activity, access to private S3 buckets, Route53 manipulation, and database theft or destruction. Researchers said the campaign also sought downstream software supply-chain propagation by seeding additional malicious packages, while Packagist removed the artifact after disclosure and defenders were urged to audit installs, inspect repositories and build logs, and rotate exposed credentials.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
On 2026-05-07, reporting attributed the malicious intercom/intercom-php 5.0.2 package to the Mini Shai-Hulud campaign. The analysis described broad credential exfiltration, arbitrary code execution in Composer contexts, and downstream supply-chain propagation using compromised publishing rights.
On 2026-05-06, a report detailed CVE-2026-42223 in Nginx UI, where improper JSON serialization exposed cryptographic secrets through a settings API to authenticated users. Those leaked secrets could be used to forge administrative JWT sessions and bypass role-based access controls.
A report published on 2026-05-05 described CVE-2026-42220 in Nginx UI, where information disclosure could expose the init user context and lead to administrative control of the management interface. The write-up also noted backup and restore abuse paths that could expose archives and enable malicious configuration restoration.
On 2026-04-30, PyPI quarantined malicious Lightning (PyTorch Lightning) releases tied to the Mini Shai-Hulud supply-chain campaign. The incident showed the operation extended beyond PHP packages into the Python ecosystem, using trusted package updates to deliver credential-stealing malware.
After identifying the compromised intercom/intercom-php package, Socket reported it to Packagist, which removed the malicious artifact. Socket also warned organizations to audit affected environments and rotate potentially exposed credentials.
On 2026-04-30, a malicious artifact replaced the legitimate intercom/intercom-php version 5.0.2 on Packagist. The tampered release turned the package into a Composer plugin that executed malware during install or update, enabling credential theft and supply-chain propagation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
resecurity.com
Open sourcecvereports.com
Open sourcecvereports.com
Open sourcecvereports.com
Open sourcesocket.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.