A malicious npm package named tw-pkgprobe-7731 disguised itself as a Twilio security research tool while attempting to collect environment data and sensitive credentials from developers. Later versions expanded to target Twilio account SIDs and Auth Tokens, exposing Twilio-related hosts and AWS metadata in the process. #tw-pkgprobe-7731 #Twilio #HackerOne #AUTH_TOKEN #ACCOUNT_SID
Keypoints
- tw-pkgprobe-7731 was published to npm by the account twdepprobe7731 in mid-August 2026.
- The package posed as an authorized Twilio bug-bounty probe to appear legitimate.
- It checked for a Twilio developer environment and exited if the target did not match.
- Some versions harvested environment data, Twilio SID-related folders, and Auth Tokens.
- The final versions probed Twilio hosts and AWS metadata while raising suspicion of malicious intent.
Read More: https://thehackernews.com/2026/09/malicious-npm-package-poses-as-twilio.html