LWA-2026-5798 MAL-2026-6373 ↗ confirmed malware

twilio-voice-js-reference-components@1.0.1

Malicious code in twilio-voice-js-reference-components (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1005 · Data from Local SystemT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

This package impersonates Twilio's voice reference components (combosquat: "twilio-voice-js-reference-components"). On installation, the preinstall hook runs index.js which collects the following from the installer's system: hostname, home directory, username, DNS server configuration, the contents of /etc/passwd and /etc/hosts, the install directory path, and the full package.json. All collected data is exfiltrated via HTTPS POST to kocxl3uxcqn73ybo0k9e4g6d74d41upj[.]oastify[.]com (port 443). The exfiltration runs automatically on npm install with no user interaction required. The package has no legitimate functionality beyond stealing system information.

analyzed by
Leitwacht
first seen
Jun 20, 2026, 12:14 PM
analyzed
Jun 20, 2026, 12:14 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.