Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials

Cybersecurity researchers have disclosed details of a malicious npm package named « tw-pkgprobe-7731 » that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily attempting to harvest sensitive data.

The package, named « tw-pkgprobe-7731, » was first uploaded to the npm registry in mid-August 2026 by an npm account named « twdepprobe7731. »