[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fonf1oexNgDFaQi_iVXHquZ7vYSzsAj3WzOp7J0uUAkQ":3},{"article":4,"iocs":49},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":26,"category":27,"article_tags":31},"538cdec4-aa9e-4b95-bee2-6c856500e563","Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials","malicious-npm-package-poses-as-twilio-bug-bounty-probe-can-exfiltrate-credential-b38195","Cybersecurity researchers have disclosed details of a malicious npm package named \"tw-pkgprobe-7731\" that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily attempting to harvest sensitive data. The package, named \"tw-pkgprobe-7731,\" was first uploaded to the npm registry in mid-August 2026 by an npm account named \"twdepprobe7731.\"","A malicious npm package named 'tw-pkgprobe-7731' was discovered, posing as a Twilio bug-bounty probe. It was designed to exfiltrate environment variables and Twilio credentials by checking for specific Twilio developer environments and scanning installed npm packages. While some versions reverted to benign functionality, earlier iterations clearly contained malicious intent, violating Twilio's security research guidelines.","Malicious npm package 'tw-pkgprobe-7731' impersonates Twilio security tool to steal credentials.","Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials Ravie LakshmananSep 22, 2026Supply Chain Attack \u002F Malware Cybersecurity researchers have disclosed details of a malicious npm package named \"tw-pkgprobe-7731\" that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily attempting to harvest sensitive data. The package, named \"tw-pkgprobe-7731,\" was first uploaded to the npm registry in mid-August 2026 by an npm account named \"twdepprobe7731.\" In total, 11 versions of the package were published in quick succession on the same day over an approximately 45-minute time period. The npm user account no longer exists as of writing. \"The first version of tw-pkgprobe-7731 posed as an authorized security research probe,\" ReversingLabs researcher Lucija Valentić said in a report published today. \"Comments inside the package describe it as an 'Authorized bug-bounty research probe (Twilio HackerOne program)' that 'runs only inside Twilio's serverless packager sandbox' and 'collects local process\u002Fhost context and writes it next to itself; no destructive action.'\" Upon execution, the package first checks if the current environment is a Twilio developer environment. It immediately exits if that's not the case. Should the check pass, the malware proceeds to extract environment variables along with system details like mounts, temporary folders, and various configurations. The gathered information is then exfiltrated via a webhook. Subsequent versions of the npm package (viz., versions 1.0.1, 1.0.2, and 1.0.3) have been found to focus on developers using Twilio APIs, specifically searching for folders tied to specific Twilio account String Identifiers (SIDs). Most importantly, it avoids taking any action if there exists a folder with a specific SID name. \"Otherwise, if matching target folders were found, it scanned installed npm packages and node_modules to inject a custom npm PoC package, creating package.json and index.js inside,\" ReversingLabs explained. Version 1.0.4 is said to have introduced an added capability to exfiltrate process.env.ACCOUNT_SID and process.env.AUTH_TOKEN, effectively compromising the victim's Twilio credentials and potentially allowing the threat actor to authorize billing and trigger communication. However, the final three versions (i.e., 1.0.8, 1.1.0, and 1.1.1) \"reverted to the basic probing profile of the package seen in version 1.0.0,\" dropping the malicious functionality incorporated in prior iterations. In addition, the last two versions have been found to conduct OSINT gathering by probing various Twilio-related hosts, such as support-api.us1.twilio[.]com, kafka-ui.au1.twilio[.]com and litellm.ai-services.corp.twilio[.]com, even fetching AWS metadata located at \"169.254.169[.]254\u002Flatest\u002Fmeta-data\u002F.\" Given these unusual course reversals, it's unclear what the end goals are and if it was published as part of a bug bounty program. However, ReversingLabs said the package versions did not follow Twilio's bug hunting guidelines listed on HackerOne. \"In other words, these packages clearly violate the basic security research guidelines Twilio established, which suggests that the packages had malicious intent,\" Valentić said. \"While the threat actor behind the campaign attempted to mask malicious features in certain releases by surrounding them with seemingly benign features and code, they made no real effort to obscure the malicious code or hide their activity. \"There is no obfuscation, typosquatting, or attempt to make the publishing npm account look legitimate – tactics we’ve routinely seen in previous campaigns. This suggests that a less sophisticated threat actor is responsible for the malicious campaign targeting Twilio developers.\" Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Cloud security, Developer Security, Malware, Supply Chain ⚡ Top Stories This Week Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing ⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It. How to Evaluate a Unified Security Platform Using a One-Incident Test Stop Trying to Control AI Behavior. Control What AI Can Reach ⭐ Featured Resources Validation Summit ’26: See How Pen Testing, Exposure Validation and BAS Work Together Red Teams: Learn How Attack Path Chaining Changes Automated Security Testing Turn Threat Intelligence Into Verified Risk With Threat-Led Penetration Testing Deploy Browser Security Monitoring in Minutes With a Single Header","https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fmalicious-npm-package-poses-as-twilio.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEikMlDL6W0FZvq8_gscr2M3UZIVnCYorB-Ip2G6To6-eZ04gFyOMsf-mvbqtMkYv484O3XnKhzySe0-UQjCOMm99fUhzrpkMD-QaZkn2UIUozJ5hLwrm7kXgLkODdkUUJk4GFXEkgrg7MlXKzcQ7kKtug2RmT80RROQfVRbQQm3HdeHBzAzhAjQ9bUf5eaT\u002Fs1600\u002Ftwilio.jpg","2026-09-22T17:58:15+00:00","2026-09-22T20:00:19.133853+00:00",8,[18,21,24],{"name":19,"type":20},"npm","product",{"name":22,"type":23},"Twilio","vendor",{"name":25,"type":20},"tw-pkgprobe-7731","26b0b636-0e31-4db1-bffb-61bdf9f20a58",{"id":26,"icon":28,"name":29,"slug":30},null,"Supply Chain","supply-chain",[32,34,39,44],{"category":33},{"id":26,"icon":28,"name":29,"slug":30},{"category":35},{"id":36,"icon":28,"name":37,"slug":38},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":40},{"id":41,"icon":28,"name":42,"slug":43},"ade75414-7914-4e23-a450-48b64546ee70","Open Source","open-source",{"category":45},{"id":46,"icon":28,"name":47,"slug":48},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[50],{"type":51,"value":52,"context":53},"ip","169.254.169.254","AWS metadata endpoint probed by malicious npm package"]