The Worm Turns to PHP: Mini Shai-Hulud’s 20-Million-Install Hijack of Intercom
ID: e9d2510f-f2a6-5578-a328-9e8eba86a35c
STIX ID: report--e9d2510f-f2a6-5578-a328-9e8eba86a35c
Feed Name: securityonline.info
Socket researchers uncovered the "Mini Shai-Hulud" supply-chain campaign that compromised intercom/intercom-php on Packagist (v5.0.2), abusing Composer's plugin mechanism to run install-time scripts that download a JavaScript runtime and execute an obfuscated router_runtime.js payload which steals cloud credentials, developer secrets, environment files, and exfiltrates them to zero.masscan.cloud; any build using the malicious artifact on April 30, 2026 should be treated as compromised and follow recommended remediation (audit, remove artifact, rotate credentials, inspect repositories).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
