LWA-2026-6954 MAL-2026-12813 ↗ confirmed malware

twilio-functions@99.99.99

Malicious code in twilio-functions (npm)

Analysis

Five combosquat packages (twilio-functions, twilio-assets, twilio-deploy, twilio-internal, twilio-serverless) all at version 99.99.99 contain an identical postinstall hook that exfiltrates system metadata. On install, index.js collects hostname, username, home directory, current working directory, platform, architecture, NODE_ENV, and CI environment variables, then POSTs the data to webhook[.]site/42ce0f0e-a0a0-41b5-b157-1c0f918e064f. If that HTTPS request fails, it falls back to a DNS callback via HTTP GET to 2b22ede784d5[.]oast[.]fun. The packages have no repository, no description, and no legitimate functionality — they are reconnaissance implants targeting developers who may confuse them with official Twilio packages.

analyzed by
Leitwacht
first seen
Jul 20, 2026, 08:16 AM
analyzed
Jul 20, 2026, 08:17 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.