Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Intercom’s npm Package Compromised in Ongoing Mini Shai-Hulud Worm Attack

Blog post from Socket

Post Details
Company
Date Published
Author
Socket Research Team
Word Count
914
Company Posts That Month
32
Language
English
Hacker News Points
-
Post removed?
No
Summary

A significant security breach involving the npm package [email protected], used for Intercom’s Node.js client, has been identified, with malicious code introduced in this version that compromises developer and CI/CD environments. The compromised package, downloaded approximately 360,000 times weekly, contains two new files, setup.mjs and router_runtime.js, which respectively run a preinstall script to download an unverified Bun binary and collect sensitive credentials such as Kubernetes and Vault credentials from local environments. These credentials are encrypted and sent through GitHub API, mirroring tactics from previous supply chain attacks. This attack is possibly linked to the TeamPCP group, known for similar past campaigns, and involves suspicious GitHub activity, including the creation of repositories with cryptic names and unauthorized changes to repositories in the intercom organization. Developers are advised to remove the malicious version, downgrade to a safer version, rotate exposed credentials, and scrutinize affected systems, especially those using sensitive tokens. The breach is under investigation, and users are urged to monitor updates as more information becomes available.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 5 1,821 338 111 +22%
Kubernetes 2 2,306 381 103 +25%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.