-= Per source details. Do not edit below this line.=-
On preinstall/postinstall, probe.js checks whether cwd matches a Twilio Serverless build path (/tmp/AC<32hex>/) and, if so, copies daemon.js to /tmp/.npm-helper.js and spawns it as a detached background process via process.execPath. The daemon polls /tmp every 80ms for sibling directories whose names match Twilio account SIDs (AC followed by 32 hex chars) and POSTs the discovered account/service/package identifiers to a hardcoded https://webhook.site/cc08d9d9-232a-42a2-8d55-0f75cb5e0e67 endpoint. For matching directories it captures process.env.ACCOUNTSID and a prefix of process.env.AUTHTOKEN and writes them to a proof file. The daemon also writes an 'injected-by-other-tenant' module into sibling build trees and appends a payload (marked /XTENANT_PROOF/) into runtime-handler's main file so that a different tenant's execution context runs attacker-authored code that captures that tenant's ACCOUNTSID and AUTHTOKEN prefix. package.json description and code comments frame the package as an authorized Twilio HackerOne bug-bounty probe; that self-labeling does not change the mechanical behavior, which is an install-time dropper, cross-tenant code injection, and remote exfiltration to a third-party webhook endpoint.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-017944",
"import_time": "2026-08-15T16:07:55.493773897Z",
"sha256": "12551ba52a9605fc8ce1e13b750671d201dcf2a6e23d03f5a23b15236f2fa49b",
"versions": [
"1.0.5"
],
"source": "amazon-inspector",
"modified_time": "2026-08-15T15:54:49Z"
},
{
"import_time": "2026-08-15T16:07:55.250041903Z",
"id": "IN-MAL-2026-017941",
"sha256": "8c5bd96b3900084739d3e28247634c49766832d455af73e6cc22186d7ec7952e",
"modified_time": "2026-08-15T15:54:17Z",
"source": "amazon-inspector",
"versions": [
"1.1.1"
]
},
{
"import_time": "2026-08-15T16:07:55.396526745Z",
"id": "IN-MAL-2026-017943",
"sha256": "d0bdf8c78469e1121c3bd1fd0d9010ba672926b66bf4f8e907f65f1c1ebb4d35",
"modified_time": "2026-08-15T15:54:39Z",
"source": "amazon-inspector",
"versions": [
"1.0.3"
]
},
{
"id": "IN-MAL-2026-017939",
"import_time": "2026-08-15T16:07:55.050479557Z",
"sha256": "eee6f0c71df2a2ef9142bdc4b270b649910a28f2e59f84d9c0bc62d24a018ba5",
"versions": [
"1.0.0"
],
"source": "amazon-inspector",
"modified_time": "2026-08-15T15:53:59Z"
},
{
"id": "IN-MAL-2026-017945",
"import_time": "2026-08-15T16:07:55.554012474Z",
"sha256": "f91db73c850bd6bdd8e6ea21908a412a86b0185ef4029483b48ea36726c60c43",
"modified_time": "2026-08-15T15:55:01Z",
"source": "amazon-inspector",
"versions": [
"1.1.0"
]
},
{
"id": "IN-MAL-2026-017942",
"import_time": "2026-08-15T16:07:55.339014087Z",
"sha256": "faa849c4d64612dfc4a6659667d4fe89f7ce517fb7e57f092ab395c97b4b0b57",
"versions": [
"1.0.1"
],
"source": "amazon-inspector",
"modified_time": "2026-08-15T15:54:27Z"
},
{
"import_time": "2026-08-15T16:07:54.978769734Z",
"id": "IN-MAL-2026-017938",
"sha256": "69b03cf519ef8c8fe288a85c0efd9a1f3a0d44f9d819ba2ca7c8fa42e5124695",
"modified_time": "2026-08-15T15:53:49Z",
"source": "amazon-inspector",
"versions": [
"1.0.7"
]
},
{
"id": "IN-MAL-2026-017940",
"import_time": "2026-08-15T16:07:55.186904909Z",
"sha256": "854deb546cd78fcfcd08bd8980b461497717936fdf26b3034512644686e0acbf",
"versions": [
"1.0.4"
],
"source": "amazon-inspector",
"modified_time": "2026-08-15T15:54:08Z"
},
{
"id": "IN-MAL-2026-017946",
"import_time": "2026-08-15T16:07:55.66273925Z",
"sha256": "89bba0d3698ca4425dedb7e1daea2e6f4231872c0fe7e7e42b50abaaf257fcfc",
"versions": [
"1.0.6"
],
"source": "amazon-inspector",
"modified_time": "2026-08-15T15:55:08Z"
}
]
}[
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
}
]
{
"evidence_files": [
{
"path": "probe.js",
"tlsh": "0121dd9b36350768c2911adf906f62122eb3e722798494e5fedc646f5f870045a738f8",
"sha256": "2e5adf40d8484cddeed88f54d362aa6bff535d08a647c5e33d313de12c682029"
},
{
"path": "daemon.js",
"tlsh": "1681a4c249b3a35c0be5914fc3ae1300e177a15a75828598b4ace5ce9f4366c439fbbc",
"sha256": "fe2f8343224c9d4252da0e11c98e85eb0be96edbdaa81b4e90c3a230ec19d846"
},
{
"path": "package.json",
"tlsh": "2ae026608c04513328d046b92a93914ebd20ca1e0206bb3456b300ac6ae6732043764e",
"sha256": "fc90732f4d6b49af7327b0ba5441786a7a4ab0b0127fe04bc2ddf14b702d788d"
}
],
"package_integrity": [
{
"filename": "tw-pkgprobe-7731-1.0.5.tgz",
"hashes": {
"sha1": "19c886b57a0c86e1efc82f4c4f2691f3ddc9f92c",
"sha512_sri": "sha512-MngjulSrafwxmgujtsPvNu8xhtDcgeqYbWGJxElC22x+arpJqyxxDmB0m2X4b6xg1auvWZ/YmLq0Ml7VXuEy/Q=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/tw-pkgprobe-7731/MAL-2026-14062.json"