Find notable cyber news and cases, enriched with sources, timelines, and signals.

Tw-pkgprobe-7731 malicious npm package targeting Twilio credentials

Malware Activity
First reported
Last updated
Happening score
H score 37
1 unique sources, 1 articles

Summary

Hide ▲

A malicious tw-pkgprobe-7731 npm package is posing as a Twilio security probe while stealing environment secrets, putting ACCOUNT_SID and AUTH_TOKEN at risk. The package was published through the npm registry and used a webhook to exfiltrate collected data from Twilio developer environments. Later versions expanded the theft behavior to include targeted probing of Twilio-related hosts and AWS metadata.

Related Happenings

Twilio developer-targeting malicious npm publishing campaign

Campaign
H score35 First: 22.09.2026 20:58 Last: 22.09.2026 20:58 Sources 1

How related: "This suggests that a less sophisticated threat actor is responsible for the malicious campaign targeting Twilio developers."

About this happening: A malicious npm campaign targeted Twilio developers by publishing 11 package versions in about 45 minutes and disguising the package as an authorized security prob...

Malicious npm and PyPI payment SDK typosquat packages

Malware Activity
H score40 First: 09.07.2026 18:09 Last: 09.07.2026 18:09 Sources 1

About this happening: The 17 malicious npm and PyPI packages targeted Paysafe, Skrill, and Neteller SDKs to steal system information and developer secrets, then send the data to an Ng...

IronWorm npm supply-chain infection and self-propagation

Malware Activity
H score15 First: 04.06.2026 18:25 Last: 04.06.2026 18:25 Sources 1

About this happening: IronWorm is a Rust infostealer in a npm supply-chain activity that hides behind an eBPF kernel rootkit, communicates over Tor, and targets 86 environment var...

Ghost campaign malicious npm supply-chain operation

Campaign
H score38 First: 24.03.2026 16:30 Last: 24.03.2026 16:30 Sources 1

About this happening: A malicious npm supply-chain campaign dubbed "Ghost campaign" is using fake installation logs to conceal malware delivery, increasing the chance that package installer...

Ghost campaign malicious npm package operation

Campaign
H score37 First: 24.03.2026 14:00 Last: 24.03.2026 14:00 Sources 1

About this happening: The Ghost campaign is pushing malicious npm packages that steal sudo/root credentials and enable wallet-targeting payloads, raising risk for developers using the Nod...

Timeline

  1. 22.09.2026 20:58 2 articles · 2h ago

    tw-pkgprobe-7731 masquerades as a Twilio bug-bounty probe and exfiltrates credentials

    Initial Disclosure

    The npm package tw-pkgprobe-7731 was uploaded in mid-August 2026 by the npm account twdepprobe7731 and published in 11 versions over about 45 minutes. It posed as an authorized Twilio security probe, checked whether execution was inside a Twilio developer environment, gathered environment and host details, and later exfiltrated process.env.ACCOUNT_SID and process.env.AUTH_TOKEN from Twilio-focused targets.

    Show sources