logo

Mini Shai-Hulud: A Cross-Ecosystem Supply Chain Attack on PyTorch Lightning & Intercom Client

ID: 753b4fe6-290a-5162-a373-8a08334d5605

STIX ID: report--753b4fe6-290a-5162-a373-8a08334d5605

Feed Name: Resecurity

Threat Score
90/100

Date Published: 2026-05-09

Date Updated: 2026-07-27

...
...

In late April 2026 the “Mini Shai-Hulud” campaign injected malicious releases into widely used packages across PyPI, npm and Composer by abusing stolen maintainer credentials and CI/CD tokens; the compromised packages executed code at import/install to bootstrap a Bun-based payload that harvested credentials, exfiltrated data (including via GitHub), and attempted worm-like propagation by republishing and injecting repositories—affecting multiple releases (e.g., lightning 2.6.2/2.6.3, intercom-client 7.0.4, intercom-php 5.0.2), leaving clear IOCs, hashes, and remediation guidance for rotation, downgrades and supply-chain hardening.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.