LWA-2026-11284 confirmed malware

twilio-hackerone-poc-afe6937c@1.0.0

Malicious code in twilio-hackerone-poc-afe6937c (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package runs probe.js on install (preinstall and postinstall). Inside a Twilio build-packager container (working directory matching /tmp/AC<32-hex>/), it collects host metadata — the current user id, working directory, parent process command line, AWS Lambda log stream name, and a listing of /var/task — and POSTs it as JSON to webhook[.]site/b520829e-516a-45ff-980c-173aa54fc4bc. It then spawns a detached daemon (copied to /tmp/.h1poc-daemon.js) that every 100ms scans /tmp for Twilio account build directories, reports each discovered account/service/package to the same webhook, and injects a marker package named h1-poc-marker into the node_modules of build directories belonging to a hardcoded account. The daemon sends heartbeats to the webhook every 30 seconds and exits after 15 minutes.

analyzed by
Leitwacht
first seen
Aug 14, 2026, 07:37 PM
analyzed
Aug 14, 2026, 07:38 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.