VYPR

composer · Malicious package advisory

Malware

intercom-php

GHSA-rwq7-v7c7-27gx

Malicious code in intercom-php (Packagist)

Details

**Severity:** Critical

**Affected versions:** `= 5.0.2`

## Source: google-open-source-security (0bd33abd6fda35e856f8346fda5e85913ce2cad6b4d6c315a2e7138b867760aa)
This package is malicious and was compromised as part of the Mini Shai-Hulud campaign by the TeamPCP threat actor.
The malicious payload steals credentials, and can propogate to NPM packages using credentials it finds.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/b7761686af7166956addfe864e56f0c76e088294/osv/malicious/packagist/intercom-php/MAL-2026-3637.json))

**References:**
- https://github.com/advisories/GHSA-gr3r-crp5-qrrm
- https://github.com/ossf/malicious-packages/blob/b7761686af7166956addfe864e56f0c76e088294/osv/malicious/packagist/intercom-php/MAL-2026-3637.json
- https://semgrep.dev/blog/2026/malicious-intercom-php-package-spreads-mini-shai-hulud-attack-to-packagist-via-composer-plugin
- https://socket.dev/blog/mini-shai-hulud-packagist-malicious-intercom-php-package-compromise
- https://github.com/ossf/malicious-packages/blob/9eb9855cce67283e3ce0335a9ee7f832062b1e81/osv/malicious/packagist/intercom-php/MAL-2026-3637.json
- https://github.com/advisories/GHSA-rwq7-v7c7-27gx

Compromised versions (1)

  • = 5.0.2

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.