twilio-serverless @99.99.99
Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 1:58 AM UTC
OSV ID
MAL-2026-10937
Ecosystem
npm
Summary
The package's postinstall hook executes index.js, which collects installer host identifiers (os.hostname(), os.userInfo().username, os.homedir(), process.cwd(), os.platform(), os.arch(), NODE_ENV, CI, package name/version) and POSTs them as JSON to a hardcoded webhook.site endpoint (webhook.site/42ce0f0e-a0a0-41b5-b157-1c0f918e064f), with a fallback GET to an interactsh subdomain (2b22ede784d5.oast.fun) for out-of-band DNS callback. The package name resembles Twilio's official serverless tooling and is published at version 99.99.99 with an empty description and no library functionality beyond the beacon — the shape of a typosquat / dependency-confusion probe that fingerprints internal build systems resolving to the public registry.
Source: amazon-inspector (04898e32caf2b456c8f454a78dc4556e1caf1c239c9170b602f9f5bad6f02003)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.