April 2026: Investigating: Compromised version of intercom-client npm package and intercom-php
Malicious versions of Intercom's developer packages (intercom-client@7.0.4 and intercom-php@5.0.2) were briefly published on April 30, 2026, potentially compromising credentials for developers who installed them during the affected timeframe. The compromised packages were removed and replaced with safe versions, while Intercom rotated credentials across affected systems and revoked/re-signed their iOS Distribution Certificate as a precaution. Investigation with external security partners found no evidence of unauthorized access to customer data or Intercom accounts, with impact limited to developer tooling environments.