MAL-2026-14063
Malicious code in twilio-hackerone-poc-afe6937c (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (6790435b096935699da3234140accc517ced689047a68e698cae06288939eed9) On npm install, preinstall/postinstall scripts execute `id`, read environment variables including AWS_LAMBDA_LOG_STREAM_NAME, list /var/task, and read parent process cmdline from /proc, then POST the collected host and environment metadata as JSON to a hardcoded webhook.site endpoint (https://webhook.site/b520829e-516a-45ff-980c-173aa54fc4bc). probe.js copies daemon.js to /tmp/.h1poc-daemon.js and spawns it detached via process.execPath with stdio ignored, writing pid and version to /tmp/.h1poc.pid and /tmp/.h1poc.ver so the process outlives npm install. The daemon polls /tmp every 100ms for sibling /tmp/AC<hex32> tenant directories, enumerates their service and package subpaths, and POSTs 'seen', heartbeat, and startup events (HOME, AWS_LAMBDA_FUNCTION_NAME, /var/task listing, `id` output, foreign/owned flags, tenant IDs, service and package names) to the same webhook for ~15 minutes. For tenant IDs in a hardcoded list, daemon.js writes a package.json and index.js under other tenants' `node_modules/h1-poc-marker/`, injecting a require-able module into another account's dependency tree. The package name and stated purpose reference a HackerOne proof-of-concept, but the shipped mechanisms — install-time exfiltration to an external inspection URL, a detached persistent background process, and cross-tenant writes into other accounts' node_modules — are the same primitives used in operational supply-chain attacks (host reconnaissance, persistence, dependency-tree injection).
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for twilio-hackerone-poc-afe6937c (npm). Pin to a known-safe version or switch to an alternative.
References
- https://www.npmjs.com/package/twilio-hackerone-poc-afe6937c/v/1.0.0 [PACKAGE]
- https://www.npmjs.com/package/twilio-hackerone-poc-afe6937c/v/1.0.3 [PACKAGE]
- https://www.npmjs.com/package/twilio-hackerone-poc-afe6937c/v/1.0.2 [PACKAGE]
- https://www.npmjs.com/package/twilio-hackerone-poc-afe6937c/v/1.0.4 [PACKAGE]
- https://www.npmjs.com/package/twilio-hackerone-poc-afe6937c/v/1.0.1 [PACKAGE]