{"id":3087,"date":"2026-09-22T22:11:26","date_gmt":"2026-09-22T22:11:26","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=3087"},"modified":"2026-09-22T22:11:26","modified_gmt":"2026-09-22T22:11:26","slug":"malicious-npm-package-poses-as-twilio-bug-bounty-probe-can-exfiltrate-credentials","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=3087","title":{"rendered":"Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Sep 22, 2026<\/span><\/span><span class=\"p-tags\">Supply Chain Attack \/ Malware<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEikMlDL6W0FZvq8_gscr2M3UZIVnCYorB-Ip2G6To6-eZ04gFyOMsf-mvbqtMkYv484O3XnKhzySe0-UQjCOMm99fUhzrpkMD-QaZkn2UIUozJ5hLwrm7kXgLkODdkUUJk4GFXEkgrg7MlXKzcQ7kKtug2RmT80RROQfVRbQQm3HdeHBzAzhAjQ9bUf5eaT\/s1700-nu-rw-lo-l85-e365\/twilio.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Cybersecurity researchers have <a href=\"https:\/\/www.reversinglabs.com\/blog\/malicious-npm-campaign-twilio\" target=\"_blank\">disclosed<\/a> details of a malicious npm package named \u00abtw-pkgprobe-7731\u00bb that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily attempting to harvest sensitive data.<\/p>\n<p>The package, named \u00abtw-pkgprobe-7731,\u00bb was first uploaded to the npm registry in mid-August 2026 by an npm account named \u00abtwdepprobe7731.\u00bb In total, <a href=\"https:\/\/secure.software\/npm\/packages\/tw-pkgprobe-7731\/versions\" target=\"_blank\">11 versions of the package<\/a> were published in quick succession on the same day over an approximately 45-minute time period. The npm user account no longer exists as of writing.<\/p>\n<p>\u00abThe first version of tw-pkgprobe-7731 posed as an authorized security research probe,\u00bb ReversingLabs researcher Lucija Valenti\u0107 said in a report published today.<\/p>\n<p>\u00abComments inside the package describe it as an &#8216;Authorized bug-bounty research probe (Twilio HackerOne program)&#8217; that &#8216;runs only inside Twilio&#8217;s serverless packager sandbox&#8217; and &#8216;collects local process\/host context and writes it next to itself; no destructive action.'\u00bb<\/p>\n<p>Upon execution, the package first checks if the current environment is a Twilio developer environment. It immediately exits if that&#8217;s not the case.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/trust-world-update-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYq3TvePXpW0JIC7fXyv7A1W8KQqmb-AZqza2EuPyT0k8Nm5CwHYHISFLKXSKIAyR8JRtqEFQ4zx5jADiAkZKQ08nRWG1jCRV5YAbhKua7WaDdH1L6wsI-xOkoV4brlMfK44UwU-4Q1xqWg0uNN7sZkMCzci4RXYgWMNPHTtuKua7OR4oCbmxE10u0yKnR\/s728-nu-rw-lo-l85-e365\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Should the check pass, the malware proceeds to extract environment variables along with system details like mounts, temporary folders, and various configurations. The gathered information is then exfiltrated via a webhook.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>Subsequent versions of the npm package (viz., versions 1.0.1, 1.0.2, and 1.0.3) have been found to focus on developers using Twilio APIs, specifically searching for folders tied to specific Twilio account String Identifiers (SIDs). Most importantly, it avoids taking any action if there exists a folder with a specific SID name.<\/p>\n<p>\u00abOtherwise, if matching target folders were found, it scanned installed npm packages and node_modules to inject a custom npm PoC package, creating package.json and index.js inside,\u00bb ReversingLabs explained.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgoV53Z4541pF-FWSJAV40cDp1G_pS8FGRsGMVKxiuFUG51UitUvSV8Jfr42BjQPHqwvNV_O77BRktlkLMs0zirkedG2sUYHyNVtrcXDKaZsMlljVlj_w5uX093zl5TS_l37aBhdNZpey6-joXupeLDh4KNxa-0ptiRGZ-SY0KKxiWR34A2d0fRaZN5_Ekq\/s1700-nu-rw-lo-l85-e365\/code-npm.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgoV53Z4541pF-FWSJAV40cDp1G_pS8FGRsGMVKxiuFUG51UitUvSV8Jfr42BjQPHqwvNV_O77BRktlkLMs0zirkedG2sUYHyNVtrcXDKaZsMlljVlj_w5uX093zl5TS_l37aBhdNZpey6-joXupeLDh4KNxa-0ptiRGZ-SY0KKxiWR34A2d0fRaZN5_Ekq\/s1700-nu-rw-lo-l85-e365\/code-npm.jpg\" alt=\"\" border=\"0\" data-original-height=\"752\" data-original-width=\"1395\"\/><\/a><\/div>\n<p>Version 1.0.4 is said to have introduced an added capability to exfiltrate <a href=\"https:\/\/www.twilio.com\/docs\/usage\/anti-fraud-developer-guide#account-level-protection\" target=\"_blank\">process.env.ACCOUNT_SID and process.env.AUTH_TOKEN<\/a>, effectively compromising the victim&#8217;s Twilio credentials and potentially allowing the threat actor to authorize billing and trigger communication.<\/p>\n<p>However, the final three versions (i.e., 1.0.8, 1.1.0, and 1.1.1) \u00abreverted to the basic probing profile of the package seen in version 1.0.0,\u00bb dropping the malicious functionality incorporated in prior iterations. <\/p>\n<p>In addition, the last two versions have been found to conduct OSINT gathering by probing various Twilio-related hosts, such as support-api.us1.twilio[.]com, kafka-ui.au1.twilio[.]com and litellm.ai-services.corp.twilio[.]com, even fetching AWS metadata located at \u00ab169.254.169[.]254\/latest\/meta-data\/.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/enterprise-ai-security-a\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhgJrVTpy3T5kJ7VEIro3XfMOmfqDnBU03fYT5CyFWrs2rE9BeQxs835FAS_f1yivzd7mZ7KartftPk4qs8w5Br-WzfYMXruXDQk4FiuXcvSxoA4XH93ipwJJyy2Hbs9jqs-keS9KZhCnQ2YYdv93M51kxJlE862ob-RrrEhP4DEVP3E79zMMPf43e5keoK\/s728-nu-rw-lo-l85-e365\/AI-eBook-d-2.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Given these unusual course reversals, it&#8217;s unclear what the end goals are and if it was published as part of a bug bounty program. However, ReversingLabs said the package versions did not follow <a href=\"https:\/\/hackerone.com\/twilio?type=team\" target=\"_blank\">Twilio&#8217;s bug hunting guidelines<\/a> listed on HackerOne.<\/p>\n<p>\u00abIn other words, these packages clearly violate the basic security research guidelines Twilio established, which suggests that the packages had malicious intent,\u00bb Valenti\u0107 said. \u00abWhile the threat actor behind the campaign attempted to mask malicious features in certain releases by surrounding them with seemingly benign features and code, they made no real effort to obscure the malicious code or hide their activity.<\/p>\n<p>\u00abThere is no obfuscation, typosquatting, or attempt to make the publishing npm account look legitimate \u2013 tactics we\u2019ve routinely seen in previous campaigns. This suggests that a less sophisticated threat actor is responsible for the malicious campaign targeting Twilio developers.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Sep 22, 2026Supply Chain Attack \/ Malware Cybersecurity researchers have disclosed details of a malicious npm package named \u00abtw-pkgprobe-7731\u00bb that masquerades as a security tool targeting developers integrating Twilio&hellip;<\/p>\n","protected":false},"author":1,"featured_media":3088,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[3510,446,1647,33,39,40,3508,352,3509],"class_list":["post-3087","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-bugbounty","tag-credentials","tag-exfiltrate","tag-malicious","tag-npm","tag-package","tag-poses","tag-probe","tag-twilio"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3087","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3087"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3087\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/3088"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3087"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3087"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3087"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}