Act
active
Malicious npm Package tw-pkgprobe-7731 Targets Twilio Devs, Steals Creds
- Engineer — Act: A live malicious npm package impersonating a Twilio security tool can exfiltrate credentials from developer environments. Audit npm dependency trees and CI/CD install logs for ’tw-pkgprobe-7731’ and ensure no project has pulled it since mid-August 2026.
- SOC/IR — Act: The package name ’tw-pkgprobe-7731’ (uploaded by ’twdepprobe7731’) is a concrete IOC; sweep CI/CD pipeline logs and artifact registries since mid-August 2026 for any installation or download of this package to identify potential credential exposure.
- Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.