Summary The Intercom TypeScript Library intercom-client@7.0.4 (published at 2026-04-30 at 14:41:04.098Z) has been compromised and uses a classic drop-and-execute attack pattern to run an infostealer that harvests GitHub Credentials. The attack patterns are similar to past Shai-Hulud compromises, which behave like a worm, automatically leveraging stolen credentials to infect additional npm packages. This worm behavior, […]