🚨 BREAKING: Mini Shai-Hulud has spread to Packagist. We detected a malicious intercom/intercom-php@5.0.2 package artifact tied to this campaign.
The compromised
#PHP package used Composer plugin execution to run during install/update, download Bun, and launch an obfuscated router_runtime.js credential-stealing payload.
It targeted GitHub, npm, SSH, cloud, Kubernetes, Vault, Docker, .env files, and more.
We reported it to
@packagist, which removed the malicious version.