Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials
- ID
- 27438
- Status
- summarized
- Published
- 23 Sep 2026, 1:58 AM
- Fetched
- 23 Sep 2026, 5:09 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/malicious-npm-package-poses-as-twilio.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 6.5
- Created
- 23 Sep 2026, 5:10 AM
- Tags
- Audience
- developersvibe_coderssaas_startup_founders
What happened
A malicious npm package called 'tw-pkgprobe-7731' was uploaded in mid-August 2026, posing as an authorized Twilio HackerOne bug-bounty probe. It published 11 versions in roughly 45 minutes, with version 1.0.4 specifically exfiltrating Twilio ACCOUNT_SID and AUTH_TOKEN environment variables via webhook, potentially allowing attackers to authorize billing and trigger communications on compromised accounts.
Why it matters
If you integrate Twilio APIs in any project, audit your npm dependencies for 'tw-pkgprobe-7731' and verify that your ACCOUNT_SID and AUTH_TOKEN are not exposed in environment variables accessible to unvetted packages. More broadly, this shows supply-chain attackers are now narrowly targeting specific SDK ecosystems with plausible-sounding security-tool disguises, so treat any unfamiliar npm package claiming to be an 'authorized probe' as suspicious until independently verified.
Discussion angle
How do you vet npm packages before installing them in production projects — do you check publisher history, version cadence, or sandbox first, and would your current process have caught a package like this that impersonates a vendor's own bug-bounty program?