Twilio developer-targeting malicious npm publishing campaign
Campaign
Summary
Hide ▲
Show ▼
A malicious npm campaign targeted Twilio developers by publishing 11 package versions in about 45 minutes and disguising the package as an authorized security probe. The activity used the npm registry to reach developer environments, harvest environment variables, and later steal Twilio credentials such as `process.env.ACCOUNT_SID` and `process.env.AUTH_TOKEN`. It also probed Twilio-related hosts and used a webhook for exfiltration, raising the risk of account abuse and unauthorized communication actions.
Related Happenings
Tw-pkgprobe-7731 malicious npm package targeting Twilio credentials
Malware Activity
H score37
First: 22.09.2026 20:58
Last: 22.09.2026 20:58
Sources 1
How related:
Version 1.0.4 is said to have introduced an added capability to exfiltrate process.env.ACCOUNT_SID and process.env.AUTH_TOKEN, effectively compromising the victim's Twilio credentials and potentially allowing the threat actor to authorize billing and trigger communication.
About this happening:
A malicious tw-pkgprobe-7731 npm package is posing as a Twilio security probe while stealing environment secrets, putting ACCOUNT_SID and AUTH_TOKEN at risk. The p...
Tw-pkgprobe-7731 malicious npm package targeting Twilio credentials
Malware ActivityHow related: Version 1.0.4 is said to have introduced an added capability to exfiltrate process.env.ACCOUNT_SID and process.env.AUTH_TOKEN, effectively compromising the victim's Twilio credentials and potentially allowing the threat actor to authorize billing and trigger communication.
About this happening: A malicious tw-pkgprobe-7731 npm package is posing as a Twilio security probe while stealing environment secrets, putting ACCOUNT_SID and AUTH_TOKEN at risk. The p...
MsaRAT backdoor routes C2 through Chrome or Edge
Malware Activity
H score23
First: 23.07.2026 12:59
Last: 23.07.2026 12:59
Sources 1
About this happening:
Chaos ransomware is using msaRAT, a Rust backdoor, to route C2 through headless Chrome or Microsoft Edge on a compromised Windows host. Cisco Talos...
MsaRAT backdoor routes C2 through Chrome or Edge
Malware ActivityAbout this happening: Chaos ransomware is using msaRAT, a Rust backdoor, to route C2 through headless Chrome or Microsoft Edge on a compromised Windows host. Cisco Talos...
Malicious npm packages @automagik/genie and pgserve self-propagating malware
Malware Activity
H score37
First: 24.04.2026 11:10
Last: 24.04.2026 11:10
Sources 1
About this happening:
Malicious npm packages are distributing credential-stealing malware that runs during installation and self-propagates across developer ecosystems, raising supply-chain...
Malicious npm packages @automagik/genie and pgserve self-propagating malware
Malware ActivityAbout this happening: Malicious npm packages are distributing credential-stealing malware that runs during installation and self-propagates across developer ecosystems, raising supply-chain...
UNC1069 open-source maintainer social-engineering campaign
Campaign
H score38
First: 04.04.2026 23:30
Last: 04.04.2026 23:30
Sources 1
About this happening:
UNC1069's coordinated social-engineering campaign against Node.js and npm maintainers has widened, with multiple developers reporting the same lure pattern and the potenti...
UNC1069 open-source maintainer social-engineering campaign
CampaignAbout this happening: UNC1069's coordinated social-engineering campaign against Node.js and npm maintainers has widened, with multiple developers reporting the same lure pattern and the potenti...
Latest development: 06.04.2026 23:55
Security researcher Taylor Monahan and Socket reported that members of the open source software community, including Socket engineers and CEO Feross Aboukhadijeh, were targeted by the same slow-burn LinkedIn, Slack, and Microsoft Teams social engineering playbook used against Axios maintainer Jason Saayman, indicating the campaign was wider than a single Axios compromise.
Ghost campaign malicious npm package operation
Campaign
H score37
First: 24.03.2026 14:00
Last: 24.03.2026 14:00
Sources 1
About this happening:
The Ghost campaign is pushing malicious npm packages that steal sudo/root credentials and enable wallet-targeting payloads, raising risk for developers using the Nod...
Ghost campaign malicious npm package operation
CampaignAbout this happening: The Ghost campaign is pushing malicious npm packages that steal sudo/root credentials and enable wallet-targeting payloads, raising risk for developers using the Nod...
Timeline
-
22.09.2026 20:58 2 articles · 2h ago
Malicious npm package tw-pkgprobe-7731 disguises itself as a Twilio bug-bounty probe
Initial DisclosureResearchers disclosed a malicious npm package named tw-pkgprobe-7731 that impersonated an authorized Twilio HackerOne security probe for developers integrating Twilio into their applications. The package was first uploaded in mid-August 2026 by the npm account twdepprobe7731, published 11 versions in about 45 minutes, checked for Twilio developer environments, gathered environment variables and system context, exfiltrated data through a webhook, and later attempted to steal process.env.ACCOUNT_SID and process.env.AUTH_TOKEN from Twilio-related targets.
Show sources
- Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials — thehackernews.com — 22.09.2026 20:58
- Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials — thehackernews.com — 22.09.2026 20:58