Authorized security research probe (bug bounty). No-op outside the specific sandbox it was written for.
During npm installation in a specifically named temporary environment, the package performs DNS/TCP/HTTPS reconnaissance against internal Twilio infrastructure and probes a link-local cloud metadata endpoint. It saves collected responses locally as loot.json.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource reaches cloud instance metadata or link-local credential endpoints.
probe.jsView on unpkg · L2Lifecycle code scans numerous Twilio internal hosts and an internal IP.
probe.jsView on unpkg · L4When cwd matches a /tmp/AC sandbox path, it requests cloud metadata and writes results to loot.json.
probe.jsView on unpkg · L17Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource reaches cloud instance metadata or link-local credential endpoints.
probe.jsView on unpkg · L2Lifecycle code scans numerous Twilio internal hosts and an internal IP.
probe.jsView on unpkg · L4When cwd matches a /tmp/AC sandbox path, it requests cloud metadata and writes results to loot.json.
probe.jsView on unpkg · L17