twiliointernal-messaging-toolbox@99.99.99
Malicious code in twiliointernal-messaging-toolbox (npm)
Analysis
Dependency-confusion packages targeting Twilio internal namespace names (twiliointernal-messaging-toolbox, org-twilio-phone-numbers-utils, twilio-platform-request, twilio-platform-async-data-fetch). The postinstall hook runs index.js which collects hostname, username, current working directory, and the package name, then POSTs this data to webhook[.]site/42ce0f0e-a0a0-41b5-b157-1c0f918e064f.
- analyzed by
- Leitwacht
- first seen
- Jul 20, 2026, 08:28 AM
- analyzed
- Jul 20, 2026, 08:29 AM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.