Home / Companies / Twilio / Blog / Post Details
Content Deep Dive

Scan your projects for crossenv and other malicious npm packages

Blog post from Twilio

Post Details
Company
Date Published
Author
Dominik Kundel
Word Count
846
Company Posts That Month
30
Language
English
Hacker News Points
-
Post removed?
No
Summary

The malicious npm package "crossenv" scans for environment variables and posts them to a server, posing a significant threat to users with secret credentials stored in their environment variables. A list of other potentially malicious packages has been compiled by Ivan Akulov, which should be checked for in projects. To scan for infected projects, a command can be executed using `find` and `xargs`, or a PowerShell script on Windows. If a malicious package is detected, the user's secrets should be rotated immediately, and they should inform others who may have access to the shared project. Users are advised to report any found malicious packages to npm to help prevent future attacks.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 2 38 8 8 -19%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.