Proprietary · · 1 day
Twilio SDK S3 bucket served malware
An exposed S3 bucket let attackers alter Twilio's hosted TaskRouter JS SDK v1.20. The injected code loaded malvertising infrastructure from customer pages.
Twilio's TaskRouter JavaScript SDK v1.20 was served as a hosted browser dependency from media.twiliocdn.com. On 2020-07-19, attackers modified that hosted file through a misconfigured AWS S3 bucket.
The injected code set a cookie named jqueryapi1oad and requested gold.platinumus.top/track/awswrite. Twilio associated the behavior with a known malvertising campaign; the returned content led to further attacker-controlled infrastructure.
Twilio said the affected window ran from 20:12 UTC on 2020-07-19 to 05:30 UTC on 2020-07-20. Customers who pinned the script with Subresource Integrity were protected because the modified file no longer matched the expected hash.
The incident was narrow but instructive. The library source was not the only artifact that mattered; the hosted copy was production code. A public CDN object with weak write controls became part of every page that trusted it.
Appendix · Affected releases
- The web-archive lane cannot reach this artifact, checked 2026-09-02. The window is about nine hours on 2020-07-19 and 20, and the earliest capture of the taskrouter.min.js path is 2021-09-09, fourteen months later.
- All thirteen captures postdate the remediation, so there is no in-window copy to diff and no baseline question to ask. This is an absence of archival coverage, not an unidentified artifact.
References
Source record: proprietary/twilio/meta.yaml