Malicious code in twilio-functions (npm)
The npm package 'twilio-functions' version 99.99.99 is a malicious typosquatting package that executes a postinstall script to collect host system identifiers and environment variables, sending this data to an external webhook URL. It also attempts a DNS callback if the network POST fails. The package mimics the Twilio SDK namespace and appears designed for reconnaissance during installation.
AI Analysis
Technical Summary
The 'twilio-functions' npm package version 99.99.99 contains malicious code executed during the postinstall phase. This code gathers host identifiers such as hostname, username, home directory, current working directory, platform, architecture, and selected environment variables. It then sends this information as JSON to a hardcoded webhook.site URL. If the network request fails, it performs a DNS callback to an interactsh-style subdomain. The package metadata suggests it is a typosquatting or dependency confusion attempt targeting users expecting the legitimate Twilio SDK.
Potential Impact
The malicious package exfiltrates sensitive host environment information to an attacker-controlled endpoint, potentially exposing system details and environment variables. This reconnaissance data could be used for further targeted attacks or exploitation. There is no indication of direct code execution beyond data collection or active exploitation in the wild.
Mitigation Recommendations
Users should avoid installing the 'twilio-functions' package version 99.99.99 from npm, as it is a malicious typosquatting package. Verify package names carefully before installation to prevent dependency confusion attacks. Since no official patch or fix is available, removing the package and scanning for any data exfiltration indicators is recommended.
Malicious code in twilio-functions (npm)
Description
The npm package 'twilio-functions' version 99.99.99 is a malicious typosquatting package that executes a postinstall script to collect host system identifiers and environment variables, sending this data to an external webhook URL. It also attempts a DNS callback if the network POST fails. The package mimics the Twilio SDK namespace and appears designed for reconnaissance during installation.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'twilio-functions' npm package version 99.99.99 contains malicious code executed during the postinstall phase. This code gathers host identifiers such as hostname, username, home directory, current working directory, platform, architecture, and selected environment variables. It then sends this information as JSON to a hardcoded webhook.site URL. If the network request fails, it performs a DNS callback to an interactsh-style subdomain. The package metadata suggests it is a typosquatting or dependency confusion attempt targeting users expecting the legitimate Twilio SDK.
Potential Impact
The malicious package exfiltrates sensitive host environment information to an attacker-controlled endpoint, potentially exposing system details and environment variables. This reconnaissance data could be used for further targeted attacks or exploitation. There is no indication of direct code execution beyond data collection or active exploitation in the wild.
Mitigation Recommendations
Users should avoid installing the 'twilio-functions' package version 99.99.99 from npm, as it is a malicious typosquatting package. Verify package names carefully before installation to prevent dependency confusion attacks. Since no official patch or fix is available, removing the package and scanning for any data exfiltration indicators is recommended.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-12813
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a735741bf8831d539154bbb
Added to database: 08/05/2026, 15:31:13 UTC
Last enriched: 09/13/2026, 15:18:23 UTC
Last updated: 09/13/2026, 15:18:23 UTC
Views: 20
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.