Intercom-client@7.0.4 Harvesting Github Credentials
Reported 24 Jul 2026 by otx · Severity: medium
The Intercom TypeScript Library version 7.0.4 has been compromised with malicious code that harvests GitHub credentials. Upon installation, the package executes a preinstall hook that downloads the Bun runtime, then runs a payload to extract GitHub credentials using the gh auth t