Repository navigation
intercom-client v7.0.4 is compromised #518
Description
Activity
It also looks like every non-default branch was also updated with malicious code

For example: 46f2c48#diff-7d76d7533653c23b753fc7ce638cf64bdb5e419927d276af836d3a03fdf1745a
Reacted by JatinFor any devs landing here trying to figure out what to do — sharing what we observed at runtime when
intercom-client@7.0.4runs inside an actions runner. This is the same TeamPCP / Mini Shai-Hulud loader that hit@bitwarden/cli@2026.4.0(April 22) and the SAP@cap-jspackages (April 29).The publish-side diff is one line.
package.jsonfor7.0.4vs clean7.0.3is identical except for one new key:"preinstall": "node setup.mjs"
All other scripts, dependencies, and metadata are unchanged. Same publishing identity (GitHub Actions OIDC). The registry-side signal is just the new preinstall hook + the timing — static scanners that don't diff every release have nothing to flag.
What executes on
npm install:npm install intercom-client → sh → node → bun → sh → gcloud config config-helper └→ sh → az account get-access-token └→ pwsh → Az.AccountsMulti-cloud credential probing, then
router_runtime.jsexfiltration tozero.masscan.cloud(we observed 11 flows alongside credential-file access).Loader fingerprint matches the prior campaign:
setup.mjsSHA256:4066781fa830224c8bbcc3aa005a396657f9c8f9016f9a64ad44a9d7f5f45e34(identical across SAP CAP packages)__decodeScrambledcipher seed0x3039(same as Bitwarden CLI cluster 3 payload)- Russian-locale
process.exit(0)guardrail
If you ran
npm install intercom-client(or any transitive dependency that resolved to it) since 2026-04-30 14:41 UTC, treat the host as compromised:- Uninstall, clear npm cache, pin to
7.0.3or earlier in your lockfile until Intercom ships a clean7.0.5. - Rotate every secret in scope of any CI runner that touched it — GitHub tokens, npm tokens, AWS / GCP / Azure credentials, SSH keys, environment variables.
- Search every GitHub org you control for repositories with the description
"A Mini Shai-Hulud has Appeared"and for commits authored asclaude@users.noreply.github.comin the last 24 hours. - Sweep for
.vscode/tasks.json(withrunOn: folderOpen) and.claude/settings.json(with aSessionStarthook) — IDE persistence vector new in this campaign; opening an infected repo in VS Code or Claude Code re-detonates.
Happy to share the full telemetry with the team or any affected org
Reacted by Zoe Hayeshere's the run profile for 7.0.4: https://app.garnet.ai/runs/25178182242?repo=jadoonf%2Fgarnet-incident-pipeline&job=install&profile=019ddf51-76f2-7838-a44e-fba8d05a2b8b
The intercom engineering team is aware of the compromise. We are actively investigating and will share more information as it becomes available.
Additional guidance is available on our status page.
EDIT: updated link to status page
Reacted by Jatin
for more info: https://app.stepsecurity.io/oss-security-feed/intercom-client?version=7.0.4