logo

The Worm Turns to PHP: Mini Shai-Hulud’s 20-Million-Install Hijack of Intercom

ID: e9d2510f-f2a6-5578-a328-9e8eba86a35c

STIX ID: report--e9d2510f-f2a6-5578-a328-9e8eba86a35c

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-05-02

Date Updated: 2026-05-02

Author: Ddos

...
...

Socket researchers uncovered the "Mini Shai-Hulud" supply-chain campaign that compromised intercom/intercom-php on Packagist (v5.0.2), abusing Composer's plugin mechanism to run install-time scripts that download a JavaScript runtime and execute an obfuscated router_runtime.js payload which steals cloud credentials, developer secrets, environment files, and exfiltrates them to zero.masscan.cloud; any build using the malicious artifact on April 30, 2026 should be treated as compromised and follow recommended remediation (audit, remove artifact, rotate credentials, inspect repositories).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.