Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials
A malicious npm package, disguised as a Twilio security probe, was uploaded to the npm registry. The package initially attempted to steal environment variables and system details from Twilio developer environments, and l…




