Security News Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials TheHackerNews Daniel Bender 22 Sep 2026 Share Malicious npm package tw-pkgprobe-7731 targets Twilio developer environments and can exfiltrate credentials and environment data.