LWA-2026-6958 MAL-2026-10938 ↗ confirmed malware

twiliointernal-messaging-toolbox@99.99.99

Malicious code in twiliointernal-messaging-toolbox (npm)

Analysis

Dependency-confusion packages targeting Twilio internal namespace names (twiliointernal-messaging-toolbox, org-twilio-phone-numbers-utils, twilio-platform-request, twilio-platform-async-data-fetch). The postinstall hook runs index.js which collects hostname, username, current working directory, and the package name, then POSTs this data to webhook[.]site/42ce0f0e-a0a0-41b5-b157-1c0f918e064f.

analyzed by
Leitwacht
first seen
Jul 20, 2026, 08:28 AM
analyzed
Jul 20, 2026, 08:29 AM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.