{"id":26307,"date":"2026-10-08T17:00:12","date_gmt":"2026-10-09T01:00:12","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2026\/10\/08\/malicious-npm-campaign-targets-developers-integrating-twilio\/"},"modified":"2026-10-08T17:00:12","modified_gmt":"2026-10-09T01:00:12","slug":"malicious-npm-campaign-targets-developers-integrating-twilio","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2026\/10\/08\/malicious-npm-campaign-targets-developers-integrating-twilio\/","title":{"rendered":"Malicious npm campaign targets developers integrating Twilio"},"content":{"rendered":"<div class=\"rich-text_richText__UyrDZ\" data-anchor-headings=\"true\" data-component=\"rich-text\" data-reader-view=\"false\">\n<div class=\"payload-richtext\">\n<p>The volume of malware on public repositories hasn\u2019t decreased. ReversingLabs (RL) has never seen more malicious packages published on public repositories, and the overall count of malicious software is steadily rising. Looking at the metrics, npm saw around 5308 unique malicious packages published in 2024 (excluding spam). By August of this year, the number of malicious npm packages reached 5723, exceeding the total for all of 2024 in just eight months. And the number of malicious packages  continues to grow. <\/p>\n<div class=\"rich-media_container__AH6jG media-block_mediaBlock__nZBDJ\" data-position=\"center\" data-restrict=\"true\" data-size=\"fill\">\n<div class=\"rich-media_media__trppT\"><template id=\"P:7\"><\/template><\/p>\n<div class=\"rich-media_overlay__LSRfe\"><svg aria-hidden=\"true\" class=\"lucide lucide-expand\" fill=\"none\" height=\"24\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" viewbox=\"0 0 24 24\" width=\"24\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><template id=\"P:8\"><\/template><template id=\"P:9\"><\/template><template id=\"P:a\"><\/template><template id=\"P:b\"><\/template><template id=\"P:c\"><\/template><template id=\"P:d\"><\/template><template id=\"P:e\"><\/template><template id=\"P:f\"><\/template><\/svg><\/div>\n<\/div>\n<\/div>\n<p><template id=\"P:10\"><\/template><template id=\"P:11\"><\/template><template id=\"P:12\"><\/template><template id=\"P:13\"><\/template><template id=\"P:14\"><\/template><template id=\"P:15\"><\/template><template id=\"P:16\"><\/template><template id=\"P:17\"><\/template><template id=\"P:18\"><\/template><template id=\"P:19\"><\/template><template id=\"P:1a\"><\/template><template id=\"P:1b\"><\/template><template id=\"P:1c\"><\/template><template id=\"P:1d\"><\/template><template id=\"P:1e\"><\/template><template id=\"P:1f\"><\/template><template id=\"P:20\"><\/template><template id=\"P:21\"><\/template><template id=\"P:22\"><\/template><template id=\"P:23\"><\/template><template id=\"P:24\"><\/template><template id=\"P:25\"><\/template><template id=\"P:26\"><\/template><template id=\"P:27\"><\/template><template id=\"P:28\"><\/template><template id=\"P:29\"><\/template><template id=\"P:2a\"><\/template><template id=\"P:2b\"><\/template><template id=\"P:2c\"><\/template><template id=\"P:2d\"><\/template><template id=\"P:2e\"><\/template><template id=\"P:2f\"><\/template><template id=\"P:30\"><\/template><template id=\"P:31\"><\/template><template id=\"P:32\"><\/template><template id=\"P:33\"><\/template><template id=\"P:34\"><\/template><template id=\"P:35\"><\/template><template id=\"P:36\"><\/template><template id=\"P:37\"><\/template><template id=\"P:38\"><\/template><\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>The volume of malware on public repositories hasn\u2019t decreased. ReversingLabs (RL) has never seen more malicious packages published on public repositories, and the overall count of malicious software is steadily rising. Looking at the metrics, npm saw around 5308 unique malicious packages published in 2024 (excluding spam). By August of this year, the number of malicious npm packages reached 5723, exceeding the total for all of 2024 in just eight months. And the number of malicious packages  cont<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[32775],"tags":[],"class_list":["post-26307","post","type-post","status-publish","format-standard","hentry","category-reversinglabs"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26307","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=26307"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26307\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=26307"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=26307"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=26307"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}