Home / Companies / Semgrep / Blog / Post Details
Content Deep Dive

Malicious Intercom PHP Package Spreads Mini Shai-Hulud Attack to Packagist via Composer Plugin

Blog post from Semgrep

Post Details
Company
Date Published
Author
-
Word Count
723
Company Posts That Month
14
Language
English
Hacker News Points
-
Post removed?
No
Summary

A recent security breach involved the compromise of the intercom/intercom-php package version 5.0.2 on Packagist, following an earlier attack on the Lightning package on PyPi, with attackers injecting malicious code that converts the package into a Composer plugin. This plugin activates during installation to download the Bun JavaScript runtime and execute an obfuscated payload that steals credentials like GitHub tokens, SSH keys, and cloud provider credentials, subsequently encrypting and exfiltrating the data. This incident is part of the expanding Mini Shai-Hulud campaign, which has shifted from targeting npm to the PHP ecosystem by exploiting Composer's plugin system for executing malicious code at installation. The attack also affected the npm package intercom-client, exposing users to risk even before the package was used. This highlights a significant vulnerability in the PHP package ecosystem, particularly due to the absence of a pre-publish quarantine, allowing malicious updates to be served quickly after a GitHub account compromise. Semgrep, a security tool, provides advisories and scanning capabilities to detect and mitigate such vulnerabilities, although it requires composer.lock for PHP projects to function effectively. The breach underscores the importance of proactive detection and rapid response to protect against such threats in software supply chains.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.