IOC Radar

Indicators are what attackers leave behind. Stolen credentials are what they arrive with.

Check Your Exposure
TLP:WHITE11 IOCs

Malicious npm campaign targets developers integrating Twilio

RE
ReversingLabs
Published September 22, 2026Original Report

Malware Families

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYunknownINFRASTRUCTUREunknownCAPABILITYMETA StealerPlayVICTIMunknown
Adversary
Infrastructure
Capability(2)
Victim

Indicators of Compromise

Indicators of Compromise11

TypeIndicatorConfidenceScoreFirst Seen
SHA13fb29cf1ef3ce6b187e724c8e7dc4b6a5dfefa50
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA116574bd0538e6ae0ad4b7c73cd85c1232478f57d
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA119c886b57a0c86e1efc82f4c4f2691f3ddc9f92c
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA135b21553837b74e1fc5ac43efd839cdc28109fdf
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA1fbc422912fa5af59ba278b30d8c1707e0fd1711b
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA1d11da34ecdc3ff768fbe79a0aaf12f2340c2dd90
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA17108c1079ac0de030902b049770e8cb822e82055
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA1c87db83ee84ae03b97b3cb11b07ad75a6c2a39ae
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA1985c294988e80f17414fb371b690080ee57387ea
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA1ea40177789e7a1b972c27c61dffff195dd85c544
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA1fe4b42d7cf37ef2137fe5259626d51cb9922309e
file-hashintel-blogmalware
Medium
53
Oct 9, 26

IOC Relationship Graph

IOC Relationship Graph11 total IOCs
SHA1
SHA111Malware2REPORTMalicious npm campaign tarMETA StealerPlay
scroll to zoom · drag to pan · click IOC to open