Skip to main content

Tag: environment variables exfiltration

1 article

Developer workstation with laptop, terminal, and notes in a brightly lit coffee shop or co-working space.

Malicious npm Package Exploits Twilio Developers for Credential Theft

Malicious actors have struck again, this time with a fake npm package called tw-pkgprobe-7731 that masquerades as a security research tool to steal credentials from unsuspecting Twilio developers. The package was cleverly designed to evade detection, only collecting and exfiltrating sensitive data when it detected a Twilio developer environment.

Analyst 207