negativeSYS.SOURCE: The Hacker News• 2026-09-22T23:28:15+05:30
Malicious npm Package Exploits Twilio Developer Environments to Exfiltrate Credentials
A malicious npm package, 'tw-pkgprobe-7731', was discovered posing as a Twilio bug-bounty tool to exfiltrate credentials and system data. The package exploited Twilio developer environments, with later versions targeting specific account identifiers and exposing sensitive information.
Cybersecurity researchers have disclosed details of a malicious npm package named "tw-pkgprobe-7731" that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily attempting to harvest sensitive data.
The package, named "tw-pkgprobe-7731," was first uploaded to the npm registry in mid-August 2026 by an npm account named "twdepprobe7731."
*** END OF TRANSMISSION ***