twilio-assets @99.99.100
Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 5:03 PM UTC
OSV ID
MAL-2026-10932
Ecosystem
npm
Summary
twilio-assets@99.99.99 is a bare-name package in the Twilio namespace whose postinstall script (node index.js, wired via package.json) runs automatically on npm install. index.js collects hostname, username, home directory, cwd, platform, arch, and selected environment variables and POSTs the JSON body to a hardcoded webhook.site capture endpoint at https://webhook.site/42ce0f0e-a0a0-41b5-b157-1c0f918e064f. On error it falls back to a GET against 2b22ede784d5.oast.fun, an interactsh out-of-band DNS/HTTP callback host, providing a secondary reconnaissance channel. The package ships no other functionality. The 99.99.99 version and the twilio-adjacent bare name are the canonical dependency-confusion shape used to force resolution over an internal package of the same name in installer build systems.
Source: amazon-inspector (91863ca63f6fc43ebc209bc8255c9f668f1e6cae5d53d2f86c847d0453bd9a0e)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.