Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: twilio (1 article)Clear

Malicious npm package impersonates Twilio bug bounty probe to exfiltrate developer credentials

ReversingLabs detailed a malicious npm package, tw-pkgprobe-7731, that masquerades as an authorized Twilio bug-bounty research probe while harvesting developer data. Uploaded in mid-August by an account that no longer exists, it shipped eleven versions within about 45 minutes. Comments inside describe it as an authorized HackerOne probe that runs only inside Twilio's serverless sandbox and takes no destructive action. On execution it first checks for a Twilio developer environment and exits otherwise, then collects environment variables plus system details like mounts and temporary folders and exfiltrates them through a webhook. Later versions specifically target developers using Twilio APIs by searching for folders tied to particular Twilio account identifiers, sharpening the credential theft.

Check
Block and audit for tw-pkgprobe-7731 across developer and build environments, then rotate Twilio credentials and API keys exposed on any affected machine.
Affected
Developers integrating Twilio who installed the package inside a matching environment had environment variables and account-linked configuration harvested and sent to an attacker webhook.
Fix
Pin and vet npm dependencies, alert on packages that fingerprint the environment before acting, and restrict outbound webhooks from build and developer hosts.