security1 publisher
A fake Twilio bug-bounty probe went up on npm eleven times on August 14
ReversingLabs found tw-pkgprobe-7731 claiming to be an authorized Twilio HackerOne research probe while it tried to exfiltrate data, and its 2026 count of malicious npm packages passed all of 2024 by the end of August.
Publishers:reversinglabs.com
Reality
- Evidence60
- Adoption25
- Hype gap+15
- Incentives78
- Confidence55