org-twilio-phone-numbers-utils @99.99.100
Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 1:58 AM UTC
OSV ID
MAL-2026-10931
Ecosystem
npm
Summary
org-twilio-phone-numbers-utils@99.99.100 is a dependency-confusion beacon package. Its package.json registers a postinstall hook that runs index.js, which collects the installer's package name, hostname (os.hostname()), username (os.userInfo()), and current working directory, then POSTs them via https to two hardcoded external destinations: webhook.site/42ce0f0e-a0a0-41b5-b157-1c0f918e064f and 8060h91v8p1bvvr24e3r8s3z4qahy7mw.oastify.com (a Burp Collaborator subdomain used for out-of-band reconnaissance). The name mimics an internal org-scoped Twilio helper and the inflated 99.99.100 version is chosen to win registry resolution against a private package of the same name. Execution is automatic on npm install; the installer has no opt-in and the collected identifiers reveal internal host and user names to the attacker.
Source: amazon-inspector (5e4fc6b0b947254720bbf5062747df2f6ad0b971c623ad42db5af303317957b4)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.