Tw-pkgprobe-7731 malicious npm package targeting Twilio credentials
Malware Activity
Summary
Hide ▲
Show ▼
A malicious tw-pkgprobe-7731 npm package is posing as a Twilio security probe while stealing environment secrets, putting ACCOUNT_SID and AUTH_TOKEN at risk. The package was published through the npm registry and used a webhook to exfiltrate collected data from Twilio developer environments. Later versions expanded the theft behavior to include targeted probing of Twilio-related hosts and AWS metadata.
Related Happenings
Twilio developer-targeting malicious npm publishing campaign
Campaign
H score35
First: 22.09.2026 20:58
Last: 22.09.2026 20:58
Sources 1
How related:
"This suggests that a less sophisticated threat actor is responsible for the malicious campaign targeting Twilio developers."
About this happening:
A malicious npm campaign targeted Twilio developers by publishing 11 package versions in about 45 minutes and disguising the package as an authorized security prob...
Twilio developer-targeting malicious npm publishing campaign
CampaignHow related: "This suggests that a less sophisticated threat actor is responsible for the malicious campaign targeting Twilio developers."
About this happening: A malicious npm campaign targeted Twilio developers by publishing 11 package versions in about 45 minutes and disguising the package as an authorized security prob...
Malicious npm and PyPI payment SDK typosquat packages
Malware Activity
H score40
First: 09.07.2026 18:09
Last: 09.07.2026 18:09
Sources 1
About this happening:
The 17 malicious npm and PyPI packages targeted Paysafe, Skrill, and Neteller SDKs to steal system information and developer secrets, then send the data to an Ng...
Malicious npm and PyPI payment SDK typosquat packages
Malware ActivityAbout this happening: The 17 malicious npm and PyPI packages targeted Paysafe, Skrill, and Neteller SDKs to steal system information and developer secrets, then send the data to an Ng...
IronWorm npm supply-chain infection and self-propagation
Malware Activity
H score15
First: 04.06.2026 18:25
Last: 04.06.2026 18:25
Sources 1
About this happening:
IronWorm is a Rust infostealer in a npm supply-chain activity that hides behind an eBPF kernel rootkit, communicates over Tor, and targets 86 environment var...
IronWorm npm supply-chain infection and self-propagation
Malware ActivityAbout this happening: IronWorm is a Rust infostealer in a npm supply-chain activity that hides behind an eBPF kernel rootkit, communicates over Tor, and targets 86 environment var...
Ghost campaign malicious npm supply-chain operation
Campaign
H score38
First: 24.03.2026 16:30
Last: 24.03.2026 16:30
Sources 1
About this happening:
A malicious npm supply-chain campaign dubbed "Ghost campaign" is using fake installation logs to conceal malware delivery, increasing the chance that package installer...
Ghost campaign malicious npm supply-chain operation
CampaignAbout this happening: A malicious npm supply-chain campaign dubbed "Ghost campaign" is using fake installation logs to conceal malware delivery, increasing the chance that package installer...
Ghost campaign malicious npm package operation
Campaign
H score37
First: 24.03.2026 14:00
Last: 24.03.2026 14:00
Sources 1
About this happening:
The Ghost campaign is pushing malicious npm packages that steal sudo/root credentials and enable wallet-targeting payloads, raising risk for developers using the Nod...
Ghost campaign malicious npm package operation
CampaignAbout this happening: The Ghost campaign is pushing malicious npm packages that steal sudo/root credentials and enable wallet-targeting payloads, raising risk for developers using the Nod...
Timeline
-
22.09.2026 20:58 2 articles · 2h ago
tw-pkgprobe-7731 masquerades as a Twilio bug-bounty probe and exfiltrates credentials
Initial DisclosureThe npm package tw-pkgprobe-7731 was uploaded in mid-August 2026 by the npm account twdepprobe7731 and published in 11 versions over about 45 minutes. It posed as an authorized Twilio security probe, checked whether execution was inside a Twilio developer environment, gathered environment and host details, and later exfiltrated process.env.ACCOUNT_SID and process.env.AUTH_TOKEN from Twilio-focused targets.
Show sources
- Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials — thehackernews.com — 22.09.2026 20:58
- Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials — thehackernews.com — 22.09.2026 20:58