← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Mini Shai-Hulud Spreads to Packagist: Malicious Intercom PHP Package Follows npm Compromise
A malicious artifact of the widely-used intercom/intercom-php package version 5.0.2 was discovered on Packagist, representing an expansion of the Mini Shai-Hulud supply chain attack from npm into the PHP ecosystem. The compromised package exploits Composer plugin execution to download Bun runtime and execute an obfuscated credential-stealing payload during installation. The malicious code harvests sensitive credentials including GitHub tokens, cloud provider credentials, SSH keys, Kubernetes tokens, and HashiCorp Vault secrets from developer machines and CI/CD environments. Stolen data is encrypted using AES-256-GCM and exfiltrated to attacker-controlled infrastructure. The payload also contains propagation logic to modify GitHub repositories and npm packages using stolen credentials. With approximately 12,700 daily installs, the compromised artifact potentially reached numerous high-value development environments before removal.
MITRE ATT&CK & Malware Families
MALWARE FAMILIES
router_runtime.js
Indicators of Compromise (5 / 9 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-SHA256 | 50212a875643520353df158196b9b3be4595094125ad8d2d2c48bdd9cb04ce1f | — | 2026-05-01 | |
| FileHash-SHA256 | 66664a49edbcee0ed0d8365839707916e92d3aa06e7f26f33c9dcc58e5fc1ef3 | — | 2026-05-01 | |
| FileHash-SHA256 | 832a976d1a8d54e296e8479aedbd89fa24baa02b8409a78bf06d4d03340881bd | — | 2026-05-01 | |
| FileHash-SHA256 | 907aec5b1288057a3e0885226918b6930a62a0f348ce23de026a683238c7903e | — | 2026-05-01 | |
| FileHash-SHA256 | b084743bd16043461e68b604dde80a8b386b405eae6f66c1103fb4fd6831d4a7 | — | 2026-05-01 |