Malicious npm Package Poses as Twilio Security Tool, Steals Credentials
Researchers disclosed a malicious npm package named tw-pkgprobe-7731 that masquerades as a security tool for developers integrating Twilio while stealthily harvesting sensitive data. It was uploaded to the npm registry in mid-August 2026 by an account called twdepprobe7731.
- Package tw-pkgprobe-7731 was uploaded to npm in mid-August 2026
- Published by the npm account twdepprobe7731
- Pretends to be a security probe for Twilio integrations
- Covertly attempts to exfiltrate developers' sensitive data
Read next
Security