
Mini Shai-Hulud reaches Packagist: the intercom/intercom-php compromise explained
A supply chain attack targeting intercom/intercom-php exploited Packagist's mutable version tags to replace a legitimate release with a payload that harvested cloud credentials, SSH keys, and secrets at install time. Laravel applications and CI pipelines are among the environments most likely to be affected…





