twilio-internal @99.99.100
Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 5:03 PM UTC
OSV ID
MAL-2026-10934
Ecosystem
npm
Summary
The package's postinstall script runs index.js on npm install and collects host reconnaissance data — os.hostname(), os.userInfo().username, os.homedir(), process.cwd(), os.platform(), architecture, and selected environment variables — then POSTs the collected data to a hardcoded collector at webhook.site/42ce0f0e-a0a0-41b5-b157-1c0f918e064f. On request failure the code triggers a DNS/HTTP callback to 2b22ede784d5.oast.fun (interactsh) as an out-of-band beacon. The package name 'twilio-internal' combined with version 99.99.99 and empty metadata is consistent with a dependency-confusion lure targeting a private Twilio internal package namespace; installing it results in exfiltration of installer host identifiers to attacker-controlled infrastructure at install time.
Source: amazon-inspector (539f7f248130c1d45914d85f04e43508d482fbf5a3622a840191dbfa18086c19)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.