镜像站点 · 本页由第三方 GitHub 只读镜像提供,非 GitHub 官方站点,不接受任何登录或凭据输入。前往 github.com
Skip to content

intercom-client v7.0.4 is compromised #518

Description

@h0x0er

Activity

  1. plafleur commented on Apr 30, 2026

    @plafleur

    It also looks like every non-default branch was also updated with malicious code
    Image

    For example: 46f2c48#diff-7d76d7533653c23b753fc7ce638cf64bdb5e419927d276af836d3a03fdf1745a

  2. jadoonf commented on Apr 30, 2026

    @jadoonf

    For any devs landing here trying to figure out what to do — sharing what we observed at runtime when intercom-client@7.0.4 runs inside an actions runner. This is the same TeamPCP / Mini Shai-Hulud loader that hit @bitwarden/cli@2026.4.0 (April 22) and the SAP @cap-js packages (April 29).

    The publish-side diff is one line. package.json for 7.0.4 vs clean 7.0.3 is identical except for one new key:

    "preinstall": "node setup.mjs"

    All other scripts, dependencies, and metadata are unchanged. Same publishing identity (GitHub Actions OIDC). The registry-side signal is just the new preinstall hook + the timing — static scanners that don't diff every release have nothing to flag.

    What executes on npm install:

    npm install intercom-client → sh → node → bun → sh → gcloud config config-helper
                                               └→ sh → az account get-access-token
                                               └→ pwsh → Az.Accounts
    

    Multi-cloud credential probing, then router_runtime.js exfiltration to zero.masscan.cloud (we observed 11 flows alongside credential-file access).

    Loader fingerprint matches the prior campaign:

    • setup.mjs SHA256: 4066781fa830224c8bbcc3aa005a396657f9c8f9016f9a64ad44a9d7f5f45e34 (identical across SAP CAP packages)
    • __decodeScrambled cipher seed 0x3039 (same as Bitwarden CLI cluster 3 payload)
    • Russian-locale process.exit(0) guardrail

    If you ran npm install intercom-client (or any transitive dependency that resolved to it) since 2026-04-30 14:41 UTC, treat the host as compromised:

    1. Uninstall, clear npm cache, pin to 7.0.3 or earlier in your lockfile until Intercom ships a clean 7.0.5.
    2. Rotate every secret in scope of any CI runner that touched it — GitHub tokens, npm tokens, AWS / GCP / Azure credentials, SSH keys, environment variables.
    3. Search every GitHub org you control for repositories with the description "A Mini Shai-Hulud has Appeared" and for commits authored as claude@users.noreply.github.com in the last 24 hours.
    4. Sweep for .vscode/tasks.json (with runOn: folderOpen) and .claude/settings.json (with a SessionStart hook) — IDE persistence vector new in this campaign; opening an infected repo in VS Code or Claude Code re-detonates.

    Happy to share the full telemetry with the team or any affected org

  3. oisinhurley commented on Apr 30, 2026

    @oisinhurley

    The intercom engineering team is aware of the compromise. We are actively investigating and will share more information as it becomes available.

    Additional guidance is available on our status page.

    EDIT: updated link to status page

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions