MAL-2026-3637
Dashboard / Malicious Package / MAL-2026-3637
MAL-2026-3637
Summary: Malicious code in intercom-php (Packagist)
Details: Source: google-open-source-security (0bd33abd6fda35e856f8346fda5e85913ce2cad6b4d6c315a2e7138b867760aa) This package is malicious and was compromised as part of the Mini Shai-Hulud campaign by the TeamPCP threat actor. The malicious payload steals credentials, and can propogate to NPM packages using credentials it finds.
References: https://socket.dev/blog/mini-shai-hulud-packagist-malicious-intercom-php-package-compromise, https://semgrep.dev/blog/2026/malicious-intercom-php-package-spreads-mini-shai-hulud-attack-to-packagist-via-composer-plugin/, https://github.com/advisories/GHSA-gr3r-crp5-qrrm
Affected packages
Package
Name: intercom/intercom-php
Purl: pkg:composer/intercom/intercom-php
Affected ranges
Type: N/A
Events:
