twilio-platform-request@99.99.99
Malicious code in twilio-platform-request (npm)
Analysis
A dependency-confusion campaign targeting Twilio internal package names. Four packages (org-twilio-phone-numbers-utils, twilio-platform-request, twiliointernal-messaging-toolbox, twilio-platform-async-data-fetch) all at version 99.99.99 contain an identical postinstall script that collects the hostname, username, current working directory, and package name, then POSTs this host metadata to webhook[.]site/42ce0f0e-a0a0-41b5-b157-1c0f918e064f. The packages have no other functionality, no repository, and no description. The C2 endpoint is webhook[.]site (UUID path /42ce0f0e-a0a0-41b5-b157-1c0f918e064f).
- analyzed by
- Leitwacht
- first seen
- Jul 20, 2026, 08:28 AM
- analyzed
- Jul 20, 2026, 08:29 AM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.