Malicious npm package targets Twilio developers with data-harvesting attempts
GeneralThe package, published by an now-deleted npm account, initially presented itself as an authorized bug-bounty probe for Twilio's HackerOne program.
Read full story at SC Media →