Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

tw-pkgprobe-7731npm

tw-pkgprobe-7731 is a confirmed malicious npm package (MAL-2026-14062) that steals credentials and exfiltrates sensitive data (malicious versions 1.0.0, 1.0.1, 1.0.3…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in tw-pkgprobe-7731 (npm)

MAL-2026-14062
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall tw-pkgprobe-7731

What this malware does

On preinstall/postinstall, probe.js checks whether cwd matches a Twilio Serverless build path (/tmp/AC<32hex>/) and, if so, copies daemon.js to /tmp/.npm-helper.js and spawns it as a detached background process via process.execPath. The daemon polls /tmp every 80ms for sibling directories whose names match Twilio account SIDs (AC followed by 32 hex chars) and POSTs the discovered account/service/package identifiers to a hardcoded https://webhook.site/cc08d9d9-232a-42a2-8d55-0f75cb5e0e67 endpoint. For matching directories it captures process.env.ACCOUNT_SID and a prefix of process.env.AUTH_TOKEN and writes them to a proof file. The daemon also writes an 'injected-by-other-tenant' module into sibling build trees and appends a payload (marked /XTENANT_PROOF/) into runtime-handler's main file so that a different tenant's execution context runs attacker-authored code that captures that tenant's ACCOUNT_SID and AUTH_TOKEN prefix. package.json description and code comments frame the package as an authorized Twilio HackerOne bug-bounty probe; that self-labeling does not change the mechanical behavior, which is an install-time dropper, cross-tenant code injection, and remote exfiltration to a third-party webhook endpoint.

Malicious versions

9 flagged
1.0.01.0.11.0.31.0.41.0.51.0.61.0.71.1.01.1.1

Indicators of compromise (SHA-256)

12551ba52a9605fc8ce1e13b750671d201dcf2a6e23d03f5a23b15236f2fa49b
8c5bd96b3900084739d3e28247634c49766832d455af73e6cc22186d7ec7952e
d0bdf8c78469e1121c3bd1fd0d9010ba672926b66bf4f8e907f65f1c1ebb4d35
eee6f0c71df2a2ef9142bdc4b270b649910a28f2e59f84d9c0bc62d24a018ba5
f91db73c850bd6bdd8e6ea21908a412a86b0185ef4029483b48ea36726c60c43
faa849c4d64612dfc4a6659667d4fe89f7ce517fb7e57f092ab395c97b4b0b57
69b03cf519ef8c8fe288a85c0efd9a1f3a0d44f9d819ba2ca7c8fa42e5124695
854deb546cd78fcfcd08bd8980b461497717936fdf26b3034512644686e0acbf
89bba0d3698ca4425dedb7e1daea2e6f4231872c0fe7e7e42b50abaaf257fcfc

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for tw-pkgprobe-7731 (9 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging tw-pkgprobe-7731 across your stack and pipelines.

  2. If you installed it — respond

    tw-pkgprobe-7731 is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If tw-pkgprobe-7731 was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks tw-pkgprobe-7731 before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. tw-pkgprobe-7731 on npm has been identified as a malicious package (versions 1.0.0, 1.0.1, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7, 1.1.0, and 1 more flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-017944IN-MAL-2026-017941IN-MAL-2026-017943IN-MAL-2026-017939IN-MAL-2026-017945IN-MAL-2026-017942IN-MAL-2026-017938IN-MAL-2026-017940IN-MAL-2026-017946

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks tw-pkgprobe-7731-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore