Intercom’s npm Package Compromised in Ongoing Mini Shai-Hulud Worm Attack
Blog post from Socket
A significant security breach involving the npm package [email protected], used for Intercom’s Node.js client, has been identified, with malicious code introduced in this version that compromises developer and CI/CD environments. The compromised package, downloaded approximately 360,000 times weekly, contains two new files, setup.mjs and router_runtime.js, which respectively run a preinstall script to download an unverified Bun binary and collect sensitive credentials such as Kubernetes and Vault credentials from local environments. These credentials are encrypted and sent through GitHub API, mirroring tactics from previous supply chain attacks. This attack is possibly linked to the TeamPCP group, known for similar past campaigns, and involves suspicious GitHub activity, including the creation of repositories with cryptic names and unauthorized changes to repositories in the intercom organization. Developers are advised to remove the malicious version, downgrade to a safer version, rotate exposed credentials, and scrutinize affected systems, especially those using sensitive tokens. The breach is under investigation, and users are urged to monitor updates as more information becomes available.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 5 | 1,821 | 338 | 111 | +22% |
| Kubernetes | 2 | 2,306 | 381 | 103 | +25% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.