Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials

Executive Summary

Cybersecurity researchers uncovered a malicious npm package named "tw-pkgprobe-7731" that pretends to be a Twilio bug‑bounty probe. Uploaded in mid‑August 2026 by the npm account "twdepprobe7731", the package stealthily harvests credentials and other sensitive data from projects that install it. The tool masquerades as a legitimate security utility, luring developers into adding it to their Twilio‑integrated applications.


Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-09-22T17:58:15+00:00 - Category: threat-intel

Original Description: Cybersecurity researchers have disclosed details of a malicious npm package named "tw-pkgprobe-7731" that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily attempting to harvest sensitive data. The package, named "tw-pkgprobe-7731," was first uploaded to the npm registry in mid-August 2026 by an npm account named "twdepprobe7731."

"You are the only person on earth who can use your ability."

— Zig Ziglar
Source: The Hacker News