The record
Written from the 1 report below. Nothing here is unsourced.
- A malicious npm package named tw-pkgprobe-7731 was uploaded to the npm registry to target developers using Twilio services.
- The software masquerades as an authorized bug-bounty research probe while attempting to exfiltrate sensitive environment variables, system configurations, and credentials.
- Later iterations of the package targeted specific Twilio account identifiers to inject custom code into developer environments.
- The malicious activity indicates a violation of established security research guidelines.
What to watch next
- Future discovery of similar campaigns targeting developer platforms
- Analysis of the threat actor behind the non-obfuscated malware
- Updates on potential downstream compromises resulting from the exfiltrated Twilio credentials
Who said what2
Only words found exactly in the article are shown, attributed and linked to the line they came from.
Lucija Valentić
ReversingLabs researcher
2 quotes · 1 outlet
“The first version of tw-pkgprobe-7731 posed as an authorized security research probe”
In the article
…account named "twdepprobe7731." In total, 11 versions of the package were published in quick succession on the same day over an approximately 45-minute time period. The npm user account no longer exists as of writing. " The first version of tw-pkgprobe-7731 posed as an authorized security research probe ," ReversingLabs researcher Lucija Valentić said in a report published today. "Comments inside the package describe it as an 'Authorized bug-bounty research probe (Twilio HackerOne program)' that 'runs only inside…
“In other words, these packages clearly violate the basic security research guidelines Twilio established, which suggests that the packages had malicious intent”
In the article
…it's unclear what the end goals are and if it was published as part of a bug bounty program. However, ReversingLabs said the package versions did not follow Twilio's bug hunting guidelines listed on HackerOne. " In other words, these packages clearly violate the basic security research guidelines Twilio established, which suggests that the packages had malicious intent ," Valentić said. "While the threat actor behind the campaign attempted to mask malicious features in certain releases by surrounding them with seemingly benign features and code, they made no real effort to obscure the…
Coverage1
All filed from India
Named United States · Twilio · HackerOne · Lucija Valentić · npm · ReversingLabs · tw-pkgprobe-7731
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
