Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Mini Shai-Hulud Spreads to Packagist: Malicious Intercom PHP Package Follows npm Compromise

Blog post from Socket

Post Details
Company
Date Published
Author
Socket Research Team
Word Count
1,340
Company Posts That Month
32
Language
English
Hacker News Points
-
Post removed?
No
Summary

A recent security breach involving the PHP package intercom/intercom-php has exposed a sophisticated supply chain attack, known as Mini Shai-Hulud, which has expanded from npm to Packagist, highlighting vulnerabilities in software ecosystems. The compromised version 5.0.2 of the package was manipulated to execute malicious code during installation or update by exploiting Composer's plugin system, allowing it to steal credentials and propagate further. The attack chain connects a PyPI lightning compromise to an npm intercom-client compromise, culminating in the PHP ecosystem breach. This incident underscores the risk of ecosystem expansion in supply chain attacks and the need for developers and security teams to audit their environments, remove malicious artifacts, and rotate any potentially exposed credentials to mitigate further risks.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 11 1,821 338 111 +22%
Kubernetes 4 2,306 381 103 +25%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.