ReversingLabs: malicious npm tw-pkgprobe-7731 poses as Twilio HackerOne probe; steals ACCOUNT_SID/AUTH_TOKEN
ReversingLabs (report covered 22 September 2026) details malicious npm package tw-pkgprobe-7731 (publisher twdepprobe7731; 11 versions published ~45 minutes on 14 August 2026; account later removed). Early versions claimed to be an “Authorized bug-bounty research probe (Twilio HackerOne program)” running only in Twilio’s serverless packager sandbox; behaviour instead fingerprints Twilio developer environments, exfiltrates host/process context and environment variables via webhook, later versions specifically target Twilio ACCOUNT_SID/AUTH_TOKEN and inject into node_modules, and some builds probe Twilio-related hosts plus AWS instance metadata. Not affiliated with Twilio; RL assesses it almost certainly violates Twilio HackerOne rules of engagement (no customer/employee data exfiltration). Package no longer present under that publisher as of RL write-up. Primary: ReversingLabs blog; wire: The Hacker News 22 Sep 2026.
- Product
- npm package tw-pkgprobe-7731 (malicious; spoofs Twilio bug-bounty probe)
- Versions
- Malicious versions published 14 Aug 2026 (1.0.0 through 1.1.1 lineage per RL); publisher account removed
- Exploited in Australia?
- unknown
- Patch to
- Remove tw-pkgprobe-7731 if present; rotate any Twilio ACCOUNT_SID/AUTH_TOKEN and related secrets that may have been in process.env; audit node_modules for unexpected injected packages; pin/lockfile and block install-script surprises; do not trust packages claiming private HackerOne sandbox authority
Primary: ReversingLabs — malicious npm campaign targeting Twilio developers · Vendor: ReversingLabs — tw-pkgprobe-7731 analysis · The Hacker News — tw-pkgprobe-7731 (22 Sep 2026)
