CuraSec

Act active

Malicious npm Package tw-pkgprobe-7731 Targets Twilio Devs, Steals Creds

2026-09-23 15:27 UTC · The Hacker News · read the source ↗ #supply-chain#npm#credential-theft
  • Engineer — Act: A live malicious npm package impersonating a Twilio security tool can exfiltrate credentials from developer environments. Audit npm dependency trees and CI/CD install logs for ’tw-pkgprobe-7731’ and ensure no project has pulled it since mid-August 2026.
  • SOC/IR — Act: The package name ’tw-pkgprobe-7731’ (uploaded by ’twdepprobe7731’) is a concrete IOC; sweep CI/CD pipeline logs and artifact registries since mid-August 2026 for any installation or download of this package to identify potential credential exposure.
  • Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.