Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials
The Hacker News reported on September 22, 2026, that a malicious package published to the npm registry poses as a Twilio bug-bounty probe and is capable of exfiltrating credentials. According to the source, the package presents itself as connected to bug-bounty activity involving Twilio, a framing that the report describes as a disguise rather than a legitimate security research tool. The source states that the package can exfiltrate credentials, but it does not identify the package name, its version, the maintainer account behind it, or the specific credential types it targets. The report does not describe the package's installation behavior, the mechanism used for exfiltration, or any command-and-control infrastructure. It also does not state whether the package has been removed from npm, how many downloads it received, or whether any users installed it. No indicators of compromise, file hashes, or detection guidance are included in the source text. The only concrete details provided are the package's disguise as a Twilio bug-bounty probe and its credential-exfiltration capability, as characterized by The Hacker News.
Developers installing npm packages that appear tied to Twilio bug-bounty work could expose credentials, per the source.