twilio-voice-js-reference-components@1.0.1
Malicious code in twilio-voice-js-reference-components (npm)
Analysis
This package impersonates Twilio's voice reference components (combosquat: "twilio-voice-js-reference-components"). On installation, the preinstall hook runs index.js which collects the following from the installer's system: hostname, home directory, username, DNS server configuration, the contents of /etc/passwd and /etc/hosts, the install directory path, and the full package.json. All collected data is exfiltrated via HTTPS POST to kocxl3uxcqn73ybo0k9e4g6d74d41upj[.]oastify[.]com (port 443). The exfiltration runs automatically on npm install with no user interaction required. The package has no legitimate functionality beyond stealing system information.
- analyzed by
- Leitwacht
- first seen
- Jun 20, 2026, 12:14 PM
- analyzed
- Jun 20, 2026, 12:14 PM
Related advisories
- llm-traces-app@1.0.1
- atlasora-utils@1.0.0
- atlasora-shared@1.0.0
- atlasora-api@1.0.0
- oauth-connect@0.1.1
- log-taker1@0.1.0
- ts-bn-proto@5.8.1
- parket-flow@3.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.