Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials

Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials
A malicious npm package named tw-pkgprobe-7731 disguised itself as a Twilio security research tool while attempting to collect environment data and sensitive credentials from developers. Later versions expanded to target Twilio account SIDs and Auth Tokens, exposing Twilio-related hosts and AWS metadata in the process. #tw-pkgprobe-7731 #Twilio #HackerOne #AUTH_TOKEN #ACCOUNT_SID

Keypoints

  • tw-pkgprobe-7731 was published to npm by the account twdepprobe7731 in mid-August 2026.
  • The package posed as an authorized Twilio bug-bounty probe to appear legitimate.
  • It checked for a Twilio developer environment and exited if the target did not match.
  • Some versions harvested environment data, Twilio SID-related folders, and Auth Tokens.
  • The final versions probed Twilio hosts and AWS metadata while raising suspicion of malicious intent.

Read More: https://thehackernews.com/2026/09/malicious-npm-package-poses-as-twilio.html