twilio-hackerone-poc-afe6937c@1.0.0
Malicious code in twilio-hackerone-poc-afe6937c (npm)
Analysis
The package runs probe.js on install (preinstall and postinstall). Inside a Twilio build-packager container (working directory matching /tmp/AC<32-hex>/), it collects host metadata — the current user id, working directory, parent process command line, AWS Lambda log stream name, and a listing of /var/task — and POSTs it as JSON to webhook[.]site/b520829e-516a-45ff-980c-173aa54fc4bc. It then spawns a detached daemon (copied to /tmp/.h1poc-daemon.js) that every 100ms scans /tmp for Twilio account build directories, reports each discovered account/service/package to the same webhook, and injects a marker package named h1-poc-marker into the node_modules of build directories belonging to a hardcoded account. The daemon sends heartbeats to the webhook every 30 seconds and exits after 15 minutes.
- analyzed by
- Leitwacht
- first seen
- Aug 14, 2026, 07:37 PM
- analyzed
- Aug 14, 2026, 07:38 PM
Related advisories
- simple-date-formatter-util-14@1.0.0
- simple-date-formatter-util-13@1.0.0
- simple-date-formatter-util-2@1.0.0
- streak-metrics-math@1.0.1
- json-to-table-util@1.0.0
- api-node-sdk@2.1.6
- app-svm-layer@2.1.6
- @daylightqc/date-fmt-lite@1.1.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.