Mini Shai-Hulud: A Cross-Ecosystem Supply Chain Attack on PyTorch Lightning & Intercom Client
ID: 753b4fe6-290a-5162-a373-8a08334d5605
STIX ID: report--753b4fe6-290a-5162-a373-8a08334d5605
Feed Name: Resecurity
In late April 2026 the “Mini Shai-Hulud” campaign injected malicious releases into widely used packages across PyPI, npm and Composer by abusing stolen maintainer credentials and CI/CD tokens; the compromised packages executed code at import/install to bootstrap a Bun-based payload that harvested credentials, exfiltrated data (including via GitHub), and attempted worm-like propagation by republishing and injecting repositories—affecting multiple releases (e.g., lightning 2.6.2/2.6.3, intercom-client 7.0.4, intercom-php 5.0.2), leaving clear IOCs, hashes, and remediation guidance for rotation, downgrades and supply-chain hardening.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
