PULSE NAME
Mini Shai-Hulud Spreads to Packagist: Malicious Intercom PHP Package Follows npm Compromise
WHITE AlienVault 2026-05-01 Modified: 2026-05-04
9
IOCs
LOW VOLUME
A malicious artifact of the widely-used intercom/intercom-php package version 5.0.2 was discovered on Packagist, representing an expansion of the Mini Shai-Hulud supply chain attack from npm into the PHP ecosystem. The compromised package exploits Composer plugin execution to download Bun runtime and execute an obfuscated credential-stealing payload during installation. The malicious code harvests sensitive credentials including GitHub tokens, cloud provider credentials, SSH keys, Kubernetes tokens, and HashiCorp Vault secrets from developer machines and CI/CD environments. Stolen data is encrypted using AES-256-GCM and exfiltrated to attacker-controlled infrastructure. The payload also contains propagation logic to modify GitHub repositories and npm packages using stolen credentials. With approximately 12,700 daily installs, the compromised artifact potentially reached numerous high-value development environments before removal.
MITRE ATT&CK & Malware Families
MALWARE FAMILIES
router_runtime.js
Indicators of Compromise (2 / 9 total)
All FileHash-SHA1 FileHash-SHA256 URL hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 e69bf4b3e84e7951a7b4ded8fee8822c57630cf8 2026-05-01
FileHash-SHA1 e8a812c5ea7d8c7ed642b0d82754ced6a99025b0 2026-05-01