Incident
Published 2026-09-22
Verified 2026-09-27

ReversingLabs: malicious npm tw-pkgprobe-7731 poses as Twilio HackerOne probe; steals ACCOUNT_SID/AUTH_TOKEN

ReversingLabs (report covered 22 September 2026) details malicious npm package tw-pkgprobe-7731 (publisher twdepprobe7731; 11 versions published ~45 minutes on 14 August 2026; account later removed). Early versions claimed to be an “Authorized bug-bounty research probe (Twilio HackerOne program)” running only in Twilio’s serverless packager sandbox; behaviour instead fingerprints Twilio developer environments, exfiltrates host/process context and environment variables via webhook, later versions specifically target Twilio ACCOUNT_SID/AUTH_TOKEN and inject into node_modules, and some builds probe Twilio-related hosts plus AWS instance metadata. Not affiliated with Twilio; RL assesses it almost certainly violates Twilio HackerOne rules of engagement (no customer/employee data exfiltration). Package no longer present under that publisher as of RL write-up. Primary: ReversingLabs blog; wire: The Hacker News 22 Sep 2026.

Product
npm package tw-pkgprobe-7731 (malicious; spoofs Twilio bug-bounty probe)
Versions
Malicious versions published 14 Aug 2026 (1.0.0 through 1.1.1 lineage per RL); publisher account removed
Exploited in Australia?
unknown
Patch to
Remove tw-pkgprobe-7731 if present; rotate any Twilio ACCOUNT_SID/AUTH_TOKEN and related secrets that may have been in process.env; audit node_modules for unexpected injected packages; pin/lockfile and block install-script surprises; do not trust packages claiming private HackerOne sandbox authority

Primary: ReversingLabs — malicious npm campaign targeting Twilio developers · Vendor: ReversingLabs — tw-pkgprobe-7731 analysis · The Hacker News — tw-pkgprobe-7731 (22 Sep 2026)

breaches identity cloud