MAL-2026-16097

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/twilio-hackerone-poc-b8f21a/MAL-2026-16097.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-16097
Published
2026-09-09T17:45:31Z
Modified
2026-09-09T18:45:05Z
Summary
Malicious code in twilio-hackerone-poc-b8f21a (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (09b67e9bd1be2e2e13aae83616afffcbfdc3fb888b304dc7210be0ee39832aac)

On npm install, postinstall.js automatically executes and performs host reconnaissance and exfiltration to a hardcoded ephemeral Cloudflare Quick Tunnel at https://encryption-watch-tubes-finger.trycloudflare.com/poc-v101-escape. The script runs id, whoami, and uname; enumerates /, $HOME, and /tmp; reads /proc/self/cgroup and /proc/mounts; probes the AWS instance-metadata service at 169.254.169.254 and the ECS task-metadata agent at 127.0.0.1:51678 and reports reachability; enumerates other AC[0-9a-f]{32} Twilio account SID directories present in /tmp (excluding one hardcoded SID) to enumerate co-tenants on shared build workers; and collects Object.keys(process.env). All of the above is POSTed as JSON to the trycloudflare.com tunnel. The tunnel host is anonymous, ephemeral, and unrelated to any legitimate publisher; the package name and self-labeling as a 'HackerOne PoC' do not change the observed installer-side data-exfiltration behavior.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-019862",
            "import_time": "2026-09-09T18:22:52.799834155Z",
            "modified_time": "2026-09-09T17:45:39Z",
            "sha256": "09b67e9bd1be2e2e13aae83616afffcbfdc3fb888b304dc7210be0ee39832aac",
            "source": "amazon-inspector",
            "versions": [
                "1.0.1"
            ]
        },
        {
            "id": "IN-MAL-2026-019861",
            "import_time": "2026-09-09T18:22:52.6977821Z",
            "modified_time": "2026-09-09T17:45:31Z",
            "sha256": "70742105c087e8f7fa656a79eed09c05efe6922f83714f7d93f3ceb717daff8a",
            "source": "amazon-inspector",
            "versions": [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / twilio-hackerone-poc-b8f21a

Package

Name
twilio-hackerone-poc-b8f21a
View open source insights on deps.dev
Purl
pkg:npm/twilio-hackerone-poc-b8f21a

Affected ranges

Affected versions

1.*
1.0.0
1.0.1

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "postinstall.js",
            "sha256": "aea219357f873110eb74b3eb5dd42fff1b8541b0416512647b23825b84332088",
            "tlsh": "c75196d8fcf5a05401f34438a8bf9605e973d983898ce454b649b55b3f6d21c1a2a9ec"
        }
    ],
    "package_integrity": [
        {
            "filename": "twilio-hackerone-poc-b8f21a-1.0.1.tgz",
            "hashes": {
                "sha1": "69c1006b838bc62e261e1fd257a3fbd568b21abf",
                "sha512_sri": "sha512-O4D5PyQwD7/lmHuqHxz+oV+siXkRMlJgepvcNvgxMLOo+CG33gKdEd2Pm/tSRrYXOrNFw67D/TbzvA/9EAjR6g=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/twilio-hackerone-poc-b8f21a/MAL-2026-16097.json"