Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

[email protected] Harvesting Github Credentials

0
Medium
Published: 07/24/2026 (07/24/2026, 01:19:11 UTC)
Source: AlienVault OTX General

Description

The Intercom TypeScript Library version 7.0.4 has been compromised with malicious code that harvests GitHub credentials. Upon installation, the package executes a preinstall hook that downloads the Bun runtime, then runs a payload to extract GitHub credentials using the gh auth token command. The attack employs sophisticated C2 communication by querying GitHub's commit search API for specific strings embedded in public repositories, effectively using legitimate services to evade detection. The attack patterns mirror previous Shai-Hulud compromises, which exhibit worm-like behavior by automatically using stolen credentials to infect additional npm packages. With 361,510 weekly downloads, this compromise poses significant risk for a widespread infection wave similar to November 2025 when over 1,000 packages were affected.

Affected software

Affected versions
=7.0.4

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/24/2026, 10:56:25 UTC

Technical Analysis

[email protected] contains malicious code introduced by the Shai-Hulud threat actor. Upon installation, a preinstall hook downloads the Bun runtime and executes a payload that extracts GitHub credentials via the 'gh auth token' command. The attacker uses GitHub's commit search API as a covert command and control channel by querying for specific strings in public repositories, allowing the attack to evade detection by blending with legitimate traffic. This behavior aligns with previous Shai-Hulud campaigns that exhibit worm-like propagation by leveraging stolen credentials to compromise additional npm packages. The package's high download volume increases the potential impact of this supply chain compromise.

Potential Impact

The compromise allows attackers to steal GitHub credentials from users installing the affected package, potentially exposing sensitive repositories and credentials. The worm-like behavior of the threat actor could lead to further infections of npm packages, amplifying the supply chain risk. The use of legitimate GitHub APIs for command and control complicates detection and response efforts. No known exploits in the wild have been reported yet, but the risk remains significant due to the package's popularity.

Mitigation Recommendations

No official patch or remediation guidance is currently provided. Patch status is not yet confirmed — check the vendor advisory or official sources for updates. Until a fix is available, avoid using Intercom-client version 7.0.4. Review and rotate any GitHub credentials that may have been exposed. Monitor for suspicious activity related to GitHub tokens and npm package installations. Consider using package integrity verification and supply chain security tools to detect compromised packages.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.netskope.com/blog/shai-hulud-intercom-client-7-0-4"]
Adversary
Shai-Hulud
Pulse Id
6a62bd8f2c1c294fc422b9b7
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domainzero.masscan.cloud

Threat ID: 6a6340569c2644c7f8c593f5

Added to database: 07/24/2026, 10:37:10 UTC

Last enriched: 07/24/2026, 10:56:25 UTC

Last updated: 07/25/2026, 00:02:24 UTC

Views: 12

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses