npm

twiliointernal-messaging-toolbox @99.99.100

Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 1:58 AM UTC

Malicious

OSV ID

MAL-2026-10938

Ecosystem

npm

Summary

twiliointernal-messaging-toolbox@99.99.100 declares a postinstall hook (node index.js) that runs automatically on npm install. index.js collects the package name, os.hostname(), os.userInfo() username, and process.cwd(), serializes them as JSON, and POSTs the payload to two hardcoded attacker-controlled endpoints: webhook.site/42ce0f0e-a0a0-41b5-b157-1c0f918e064f and 8060h91v8p1bvvr24e3r8s3z4qahy7mw.oastify.com (a Burp Collaborator / OAST subdomain). The package name typosquats the Twilio brand and the 99.99.100 version is consistent with a dependency-confusion lure targeting an internal Twilio scope. Installing the package leaks installer host and user identifiers to third-party infrastructure and confirms code execution on the installer machine.

Source: amazon-inspector (329659fc03a26586a812a06bdf624c678cd4ba857da72fb95713dd0f4aa8c568)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.