⌁ CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials

September 22, 2026

Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials Ravie LakshmananSep 22, 2026Supply Chain Attack / Malware Cybersecurity researchers have disclosed details of a malicious npm package named "tw-pkgprobe-7731" that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily attempting to harvest sensitive data. The package, named "tw-pkgprobe-7731," was first uploaded to the npm registry in mid-August 2026 by an npm account named "twdepprobe7731." In total, 11 versions of the package were published in quick succession on the same day over an approximately 45-minute time period. The npm user account no longer exists as of writing. "The first version of tw-pkgprobe-7731 posed as an authorized security research probe," ReversingLabs researcher Lucija Valentić said…