npm

twilio-assets @99.99.99

Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 1:58 AM UTC

Malicious

OSV ID

MAL-2026-10932

Ecosystem

npm

Summary

twilio-assets@99.99.99 is a bare-name package in the Twilio namespace whose postinstall script (node index.js, wired via package.json) runs automatically on npm install. index.js collects hostname, username, home directory, cwd, platform, arch, and selected environment variables and POSTs the JSON body to a hardcoded webhook.site capture endpoint at https://webhook.site/42ce0f0e-a0a0-41b5-b157-1c0f918e064f. On error it falls back to a GET against 2b22ede784d5.oast.fun, an interactsh out-of-band DNS/HTTP callback host, providing a secondary reconnaissance channel. The package ships no other functionality. The 99.99.99 version and the twilio-adjacent bare name are the canonical dependency-confusion shape used to force resolution over an internal package of the same name in installer build systems.

Source: amazon-inspector (91863ca63f6fc43ebc209bc8255c9f668f1e6cae5d53d2f86c847d0453bd9a0e)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.