🚨 Two major supply chain attacks today, hitting both PyPI and npm simultaneously.
Socket detected and confirmed malicious code in lightning versions 2.6.2 and 2.6.3 on PyPI, and intercom-client version 7.0.4 on npm. Both attacks use nearly identical tooling. Both are live right now.
lightning is one of the most popular deep learning frameworks in the Python ecosystem, with millions of downloads per month. intercom-client is Intercom's official Node.js SDK, with roughly 360K weekly downloads. These are not typosquats. These are the real packages.
The payloads are almost identical across both attacks:
• Both inject an ~11MB obfuscated JavaScript file (router_runtime.js) and a setup script that downloads and executes the Bun runtime from GitHub
• Both harvest GitHub tokens, npm tokens, AWS/Azure/GCP credentials, Kubernetes secrets, Vault tokens, and CI/CD environment variables
• Both exfiltrate stolen credentials through the GitHub API
• Both execute automatically, lightning on import, intercom-client on install
The lightning attack goes further. It uses stolen GitHub tokens to commit poisoned files to every branch of every repository the token can write to, impersonating Anthropic's Claude Code as the committer ([email protected]). It also infects local npm tarballs by injecting a postinstall hook and bumping the patch version, so the next publish silently ships malware to downstream users.
In both cases, the attackers appear to have compromised maintainer accounts and used them to suppress disclosure. On the Lightning-AI GitHub, the pl-ghost account closed Socket's disclosure issue within one minute and posted a meme. On the Intercom GitHub, the nhur account closed, redacted, and retitled security reports to "N/A." Both accounts show bursts of suspicious branch-creation activity consistent with the Shai-Hulud worm's credential-probing pattern, including misspelled Dependabot impersonation branches.
The attackers posted an onion link in the Lightning-AI issue thread claiming affiliation with "Team PCP" and referencing LAPSUS$. Socket has not verified these claims. The intercom-client attack also shows direct Shai-Hulud hallmarks, including repos created with descriptions reading "A Mini Shai-Hulud has Appeared."
Socket's AI scanner flagged the malicious lightning versions 18 minutes after publication.
If you use either package:
• Remove lightning 2.6.2/2.6.3 and intercom-client 7.0.4 immediately
• Downgrade to lightning 2.6.1 / intercom-client 7.0.3
• Rotate all credentials in affected environments
• Audit repos for unauthorized commits from [email protected] and unexpected files in .claude/ or .vscode/
• More advice in our full research posts...
This is the same attacker campaign operating across two language ecosystems simultaneously. The playbook is credential theft, repo poisoning, and worm-style propagation. The scope is still being determined.
Developing story...
Google has deleted the account but I’m confident the third party AI tool that vercel mentioned in the blog post is context[.]ai based on a now removed chrome browser extension listing linked to an oauth grant in the same account id
Security incident involving Vercel. Check for the following Oauth grant in your environment http://110671459871-30f1spbu0hptbs60cb4vsmv79i7bbvqj.apps.googleusercontent[.]com
🎉 We're thrilled to announce our $22.5M Series A funding led by Cerberus Ventures, with participation from Ballistic Ventures, Forgepoint Capital, and Squadra Ventures.
Many thanks to our customers, investors, and supporters. Stay tuned!
https://t.co/3qw9nZZ3MM
Just 1 month into using @nudge_security and we’re already seeing huge improvements in SaaS visibility & security posture. 🚀
Excited to keep pushing forward with these results.
#CyberSecurity#SaaS
📣 Today's press release recaps highlights from 2024, which include more than doubling our customer base and tripling ARR!
Thank you to our customers, investors, partners, and friends who have provided invaluable feedback and support along the way. 🙏🏻
https://t.co/T87w0sPPxf
More technical details have been published by Cyberhaven. Phishing e-mail to the email address associated eith the extension and malicious Oauth grant https://t.co/stp2dRFL6a
Regarding the Cyberhaven chrome extension compromise I have reasons to believe there are other extensions affected. Pivoting by the ip address there are more domains created within the same time range resolving to the same ip address as cyberhavenext[.]pro (cont)
2024 has brought an unprecedented spike in identity-based attacks against #Okta customers, as well as attacks exploiting misconfigurations in Microsoft 365 and Google Workspace.
Learn how Nudge Security can help:
https://t.co/sWcbr10I7Z
#iam#sysadmin#itdr#ciso#macadmin
You know that feeling when you find $20 in a pair of jeans you haven't worn in awhile? We can help you find SaaS spend you didn't know about, forgot about, or is no longer needed, helping you eliminate wasted spend and fund new investments.
https://t.co/HGI2CUP2ND
#cfo#cio
🔥 Hot product news! We've extended our security posture management capabilities to include Okta, furthering your ability to harden your identity infrastructure with Nudge.
Learn more here:
https://t.co/NPHDdgThtP
#iam#okta#sysadmin#sspm#ciso#cio#grc
Using Tines for security orchestration? Now, when Nudge Security surfaces SaaS security posture findings, you can use Tines to automate the creation of JIRA tickets to help you track resolution.
https://t.co/9J8jnS0FP2
#infosec#soc#sspm#soar#tines@tines_hq
A disgruntled former Disney employee was allegedly able to use passwords for accounts that were not properly deprovisioned to access a third-party menu creation software used by Walt Disney World’s restaurants and alter the menus.
https://t.co/QYj4ASwTLR
#iam#offboarding#itdr
This month, we’re celebrating more than just Halloween: Nudge Security has officially turned TWO! 🎂
Check out some of our highlights from the last year here:
https://t.co/IsfbAmjAic
#ciso#cio#infosec#iam#grc#saas
By sending a seemingly authentic DocuSign email, attackers are able to mislead recipients into clicking on a link that redirects them to a Microsoft phishing page.
https://t.co/R6is5MqKJ3
#infosec#itdr#phishing
Join us tomorrow to see how our patented SaaS discovery method can now discover SaaS spend as well as apps, instances, and users, so you can curb SaaS spend, sprawl, and security risks all with one tool. 🙌
https://t.co/4xU2cHukIq
#saas#sysadmin#cfo#cio#ciso#infosec#grc
Our latest blog post charts the number of new genAI tools introduced over the last two years along with practical guidance for securing your genAI footprint.
https://t.co/wd8pP5n4ZD
#genAI#grc#cio#ciso#infosec