


Perceptive Security
SOC/SIEM Consultancy

Shai-Hulud Worm Pivots to Multi-Cloud: intercom-client@7.0.4 Hijacked — 361,000 Weekly Downloads, AWS, GCP, and Azure Credentials Now in Scope
Published:
1 mei 2026 om 14:24:55
Alert date:
1 mei 2026 om 15:01:38
Source:
stepsecurity.io
Supply Chain & Dependencies, Ransomware & Malware, Cloud & Virtualization
The Shai-Hulud worm has compromised a third major npm package, intercom-client@7.0.4, with 361,510 weekly downloads. This follows the compromise of mbt@1.2.48 and @cap-js/sqlite@2.2.2 packages 29 hours earlier. The malicious version was published via a hijacked GitHub Actions OIDC publishing pipeline, demonstrating active propagation through CI/CD infrastructure. The worm has pivoted to multi-cloud targeting, now seeking AWS, GCP, and Azure credentials. The attack represents a significant supply chain compromise affecting hundreds of thousands of weekly downloads across multiple npm packages.
Technical details
Mitigation steps:
Affected products:
intercom-client
mbt
@cap-js/sqlite
npm
GitHub Actions
AWS
GCP
Azure
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
