Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials
Malicious npm package tw-pkgprobe-7731 posed as a Twilio bug-bounty probe and can steal credentials.
ReversingLabs disclosed the malicious npm package tw-pkgprobe-7731, uploaded in mid-August 2026 by the account twdepprobe7731. Eleven versions appeared within about 45 minutes and were described in comments as an authorized Twilio HackerOne bug-bounty probe. After detecting a Twilio developer environment, the code collected environment variables, mounts, and configuration and sent them to a webhook. Versions 1.0.1 through 1.0.4 searched for Twilio account SID folders, injected a custom npm package, and exfiltrated ACCOUNT_SID and AUTH_TOKEN, while later builds probed Twilio hosts and the AWS instance metadata service.