Executive brief
A malicious version (7.0.4) of the intercom-client npm package—a widely-used Node.js SDK for the Intercom customer communication API—was published to npm following compromise of a developer account. During installation, the package executed an obfuscated payload that harvested sensitive credentials including cloud provider keys (AWS, GCP, Azure), API tokens, SSH keys, and Kubernetes secrets, then exfiltrated them to attacker-controlled repositories. This supply chain attack affected developers and CI/CD pipelines, exposing potentially thousands of backend systems and deployment environments to full credential compromise.
Technical details
The vulnerability is embedded malicious code (CWE-506) introduced into npm package intercom-client version 7.0.4. The compromised version was published via stolen credentials from a developer account that had legitimate npm publishing rights, bypassing normal code review. The payload executes during installation through a preinstall hook in package.json that runs setup.mjs, which downloads and executes an unverified Bun binary from GitHub. A secondary malicious file, router_runtime.js (11.7 MB obfuscated JavaScript), performs credential harvesting targeting environment variables, local configuration files, and cloud metadata services, with exfiltration through the GitHub API. The attack vector is network-based with no authentication or privileges required—exploitation occurs automatically upon package installation in any environment (developer machine, CI/CD pipeline, container). Users who installed 7.0.4 between 15:00–17:00 UTC on April 30, 2026 are affected. The attack is part of the "Mini Shai-Hulud" campaign attributed to TeamPCP. Mitigation requires immediate downgrade to version 7.0.3, rotation of all potentially exposed credentials from affected systems, and review of CI/CD logs and lock files for evidence of the compromise.
Affected products
- Intercom intercom-client 7.0.4
Timeline
- 2026-04-30: disclosed: Malicious version 7.0.4 published to npm; live for approximately 2 hours (15:00–17:00 UTC)
- 2026-04-30: patched: Package removed from npm; users advised to downgrade to 7.0.3
References
- https://github.com/intercom/intercom-node/security/advisories/GHSA-54pg-9963-v8vg
- https://github.com/intercom/intercom-node
- https://socket.dev/blog/intercom-s-npm-package-compromised-in-supply-chain-attack
- https://www.intercomstatus.com/us-hosting/incidents/01KQFN6VS6ARP1XBR1K1SBYY59
- https://www.wiz.io/blog/mini-shai-hulud-supply-chain-sap-npm