Skip to content

Malicious code in intercom-php (Packagist)

Malware Published Aug 19, 2026 to the GitHub Advisory Database

Package

composer intercom/intercom-php (Composer)

Affected versions

= 5.0.2

Patched versions

None

Description

Source: google-open-source-security (0bd33abd6fda35e856f8346fda5e85913ce2cad6b4d6c315a2e7138b867760aa)

This package is malicious and was compromised as part of the Mini Shai-Hulud campaign by the TeamPCP threat actor.
The malicious payload steals credentials, and can propogate to NPM packages using credentials it finds.


Credit: OpenSSF (source)

References

Published to the GitHub Advisory Database Aug 19, 2026
Reviewed Aug 19, 2026

EPSS score

Weaknesses

Embedded Malicious Code

The product contains code that appears to be malicious in nature. Learn more on MITRE.

GHSA ID

GHSA-45gr-fjmv-r4rw

Source code

No known source code
Improvements are not currently accepted on this advisory because this package is malware and has no patched versions. If there is something to change, please open an issue at https://github.com/github/advisory-database/issues.