LWA-2026-6956 MAL-2026-10936 ↗ confirmed malware

twilio-platform-request@99.99.99

Malicious code in twilio-platform-request (npm)

T1059 · Command and Scripting InterpreterT1546.016 · Installer Packages

Analysis

A dependency-confusion campaign targeting Twilio internal package names. Four packages (org-twilio-phone-numbers-utils, twilio-platform-request, twiliointernal-messaging-toolbox, twilio-platform-async-data-fetch) all at version 99.99.99 contain an identical postinstall script that collects the hostname, username, current working directory, and package name, then POSTs this host metadata to webhook[.]site/42ce0f0e-a0a0-41b5-b157-1c0f918e064f. The packages have no other functionality, no repository, and no description. The C2 endpoint is webhook[.]site (UUID path /42ce0f0e-a0a0-41b5-b157-1c0f918e064f).

analyzed by
Leitwacht
first seen
Jul 20, 2026, 08:28 AM
analyzed
Jul 20, 2026, 08:29 AM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.