-= Per source details. Do not edit below this line.=-
On npm install, postinstall.js automatically executes and performs host reconnaissance and exfiltration to a hardcoded ephemeral Cloudflare Quick Tunnel at https://encryption-watch-tubes-finger.trycloudflare.com/poc-v101-escape. The script runs id, whoami, and uname; enumerates /, $HOME, and /tmp; reads /proc/self/cgroup and /proc/mounts; probes the AWS instance-metadata service at 169.254.169.254 and the ECS task-metadata agent at 127.0.0.1:51678 and reports reachability; enumerates other AC[0-9a-f]{32} Twilio account SID directories present in /tmp (excluding one hardcoded SID) to enumerate co-tenants on shared build workers; and collects Object.keys(process.env). All of the above is POSTed as JSON to the trycloudflare.com tunnel. The tunnel host is anonymous, ephemeral, and unrelated to any legitimate publisher; the package name and self-labeling as a 'HackerOne PoC' do not change the observed installer-side data-exfiltration behavior.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-019862",
"import_time": "2026-09-09T18:22:52.799834155Z",
"modified_time": "2026-09-09T17:45:39Z",
"sha256": "09b67e9bd1be2e2e13aae83616afffcbfdc3fb888b304dc7210be0ee39832aac",
"source": "amazon-inspector",
"versions": [
"1.0.1"
]
},
{
"id": "IN-MAL-2026-019861",
"import_time": "2026-09-09T18:22:52.6977821Z",
"modified_time": "2026-09-09T17:45:31Z",
"sha256": "70742105c087e8f7fa656a79eed09c05efe6922f83714f7d93f3ceb717daff8a",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "postinstall.js",
"sha256": "aea219357f873110eb74b3eb5dd42fff1b8541b0416512647b23825b84332088",
"tlsh": "c75196d8fcf5a05401f34438a8bf9605e973d983898ce454b649b55b3f6d21c1a2a9ec"
}
],
"package_integrity": [
{
"filename": "twilio-hackerone-poc-b8f21a-1.0.1.tgz",
"hashes": {
"sha1": "69c1006b838bc62e261e1fd257a3fbd568b21abf",
"sha512_sri": "sha512-O4D5PyQwD7/lmHuqHxz+oV+siXkRMlJgepvcNvgxMLOo+CG33gKdEd2Pm/tSRrYXOrNFw67D/TbzvA/9EAjR6g=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/twilio-hackerone-poc-b8f21a/MAL-2026-16097.json"