Fake Twilio npm Probe Hid Credential Theft
Researchers say a package posing as an authorized Twilio bug-bounty probe went through 11 versions before trying to exfiltrate API credentials.
2 results for “api credentials”
Researchers say a package posing as an authorized Twilio bug-bounty probe went through 11 versions before trying to exfiltrate API credentials.
Attackers used a compromised credential from the Ribon app to pull customer data from hundreds of online stores, exposing a soft spot in e-commerce supply chains.