악성 npm 패키지 'tw-pkgprobe-7731'이 트윌리오 보안 도구를 가장해 민감한 데이터를 탈취하려 시도하고 있습니다.
사이버 보안 연구자들은 'tw-pkgprobe-7731'이라는 악성 npm 패키지에 대한 자세한 내용을 밝혔습니다. 이 패키지는 트윌리오를 애플리케이션에 통합하는 개발자들을 겨냥한 보안 도구로 가장하고 있으며, 민감한 데이터를 몰래 수집하려고 시도하고 있습니다. 이 패키지는 2026년 8월 중반에 'twdepprobe7731'이라는 npm 계정에 의해 처음 업로드되었습니다.
Malicious npm package 'tw-pkgprobe-7731' poses as a Twilio security tool to stealthily harvest sensitive data.
Cybersecurity researchers have disclosed a malicious npm package named 'tw-pkgprobe-7731.' This package masquerades as a security tool aimed at developers integrating Twilio into their applications while attempting to stealthily harvest sensitive data. It was first uploaded to the npm registry in mid-August 2026 by a user account named 'twdepprobe7731.'