twiliointernal-messaging-toolbox @99.99.100
Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 1:58 AM UTC
OSV ID
MAL-2026-10938
Ecosystem
npm
Summary
twiliointernal-messaging-toolbox@99.99.100 declares a postinstall hook (node index.js) that runs automatically on npm install. index.js collects the package name, os.hostname(), os.userInfo() username, and process.cwd(), serializes them as JSON, and POSTs the payload to two hardcoded attacker-controlled endpoints: webhook.site/42ce0f0e-a0a0-41b5-b157-1c0f918e064f and 8060h91v8p1bvvr24e3r8s3z4qahy7mw.oastify.com (a Burp Collaborator / OAST subdomain). The package name typosquats the Twilio brand and the 99.99.100 version is consistent with a dependency-confusion lure targeting an internal Twilio scope. Installing the package leaks installer host and user identifiers to third-party infrastructure and confirms code execution on the installer machine.
Source: amazon-inspector (329659fc03a26586a812a06bdf624c678cd4ba857da72fb95713dd0f4aa8c568)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.