A malicious npm package, tw-pkgprobe-7731, impersonated an authorized Twilio HackerOne bug-bounty research tool to target developers integrating Twilio APIs. Published in 11 rapid-fire versions by the unrelated npm account twdepprobe7731, it profiled developer environments and exfiltrated host and environment data through a webhook; version 1.0.4 specifically attempted to steal ACCOUNT_SID and AUTH_TOKEN credentials.
Some releases searched for Twilio account-SID-related directories and attempted to inject a custom proof-of-concept package into installed packages and node_modules; later versions also performed OSINT against Twilio-related hosts and the AWS instance-metadata endpoint. ReversingLabs said the package violated Twilio's bug-bounty rules and naming requirements, assessed the campaign as likely low sophistication due to its unobfuscated code and weak impersonation, and reported that npm removed the package after notification.

Trace attribution and downstream blast radius.
5 events from the most recent confirmed update back to the earliest known activity.
Later package versions reverted to basic environment probing, while the final releases probed Twilio-related hosts for OSINT and attempted to request AWS instance metadata from 169.254.169.254. The AWS metadata was not used or exfiltrated, according to ReversingLabs.
Version 1.0.4 attempted to exfiltrate the Twilio process.env.ACCOUNT_SID and process.env.AUTH_TOKEN values through a webhook, credentials that could enable unauthorized API activity, communications, and billing charges.
Versions 1.0.1 through 1.0.3 searched for directories associated with targeted Twilio account SIDs, scanned installed npm packages and node_modules directories, and wrote custom package.json and index.js files into targeted locations.
The unrelated npm account twdepprobe7731 published tw-pkgprobe-7731, falsely presenting it as an authorized Twilio HackerOne research probe. Its initial version checked for a Twilio development environment and exfiltrated collected environment and host data to an external webhook when the check succeeded.
npm removed the tw-pkgprobe-7731 packages after ReversingLabs notified the registry of the malicious campaign.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 11 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.