Mini Shai-Hulud Spreads to Packagist: Malicious Intercom PHP Package Follows npm Compromise
Blog post from Socket
A recent security breach involving the PHP package intercom/intercom-php has exposed a sophisticated supply chain attack, known as Mini Shai-Hulud, which has expanded from npm to Packagist, highlighting vulnerabilities in software ecosystems. The compromised version 5.0.2 of the package was manipulated to execute malicious code during installation or update by exploiting Composer's plugin system, allowing it to steal credentials and propagate further. The attack chain connects a PyPI lightning compromise to an npm intercom-client compromise, culminating in the PHP ecosystem breach. This incident underscores the risk of ecosystem expansion in supply chain attacks and the need for developers and security teams to audit their environments, remove malicious artifacts, and rotate any potentially exposed credentials to mitigate further risks.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 11 | 1,821 | 338 | 111 | +22% |
| Kubernetes | 4 | 2,306 | 381 | 103 | +25% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.