VDB
KO

MAL-2026-10938

Malicious code in twiliointernal-messaging-toolbox (npm)

Details

The twiliointernal-messaging-toolbox package is a dependency-confusion squat of Twilio's npm namespace published by user 'yuva2210' (maintainer email charankumarj2004@gmail.com) at sentinel versions 99.99.99 and 99.99.100, chosen to outrank any internal/private version and win resolution against a private registry. The npm description is empty and the package provides no legitimate functionality; the name mimics a plausible internal Twilio package so that a misconfigured resolver installs this public lookalike instead of the intended private dependency. It belongs to the same campaign as the actor's twilio-serverless/twilio-assets/twilio-deploy/twilio-internal squats and beacons to the same webhook.site collector.

The package declares a postinstall hook ("node index.js") that executes automatically on a bare npm install with no consent gate. The index.js payload performs environment reconnaissance: it collects the npm package name (npm_package_name), os.hostname(), the OS username (os.userInfo().username), and the current working directory, serializes them to JSON, and exfiltrates the bundle via HTTPS POST to a hardcoded anonymous dead-drop at https://webhook.site/42ce0f0e-a0a0-41b5-b157-1c0f918e064f. Request errors are swallowed so the install appears to succeed.

Two iterations were published: version 99.99.99 (payload 494 bytes, sha256 prefix 0ec56ada88db35b6) beacons only to the webhook.site collector, while version 99.99.100 (payload 688 bytes, sha256 prefix cebf45a0feba28b3) additionally beacons to a redundant out-of-band callback at 8060h91v8p1bvvr24e3r8s3z4qahy7mw.oastify.com, ensuring the reconnaissance lands even where HTTPS egress to webhook.site is blocked. Both payloads are byte-identical across all four packages in this sub-cluster (twiliointernal-messaging-toolbox, org-twilio-phone-numbers-utils, twilio-platform-request, twilio-platform-async-data-fetch).

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (329659fc03a26586a812a06bdf624c678cd4ba857da72fb95713dd0f4aa8c568) twiliointernal-messaging-toolbox@99.99.100 declares a postinstall hook (node index.js) that runs automatically on npm install. index.js collects the package name, os.hostname(), os.userInfo() username, and process.cwd(), serializes them as JSON, and POSTs the payload to two hardcoded attacker-controlled endpoints: webhook.site/42ce0f0e-a0a0-41b5-b157-1c0f918e064f and 8060h91v8p1bvvr24e3r8s3z4qahy7mw.oastify.com (a Burp Collaborator / OAST subdomain). The package name typosquats the Twilio brand and the 99.99.100 version is consistent with a dependency-confusion lure targeting an internal Twilio scope. Installing the package leaks installer host and user identifiers to third-party infrastructure and confirms code execution on the installer machine.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / twiliointernal-messaging-toolbox
Introduced in: 0

No fixed version published yet for twiliointernal-messaging-toolbox (npm). Pin to a known-safe version or switch to an alternative.

References