{"id":"MAL-2026-17664","summary":"Malicious code in wix-ssr-thunderbolt-grid-polyfill (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (b6e0013701f6ab53085883b09092f0cd5ae9aaaab51a9f0e9de5aa68946ae9e1)\nThe package ships two minified bundles — dist/poc-model.bundle.min.js and dist/poc-bootstrap.bundle.min.js — that are wired as the model and bootstrap batches in rb_wixui.thunderbolt.manifest.min.json under baseURL https://static.parastorage.com/unpkg/wix-ssr-thunderbolt-grid-polyfill@0.1.0/dist/. When the manifest resolves inside a Wix Thunderbolt SSR worker, poc-model.bundle.min.js collects Node version, cwd, hostname, POD_IP, uid, os.networkInterfaces() output, the contents of /etc/hosts and /etc/resolv.conf, environment variable names, a DNS lookup of bo.wix.com, and the response bodies of a localhost port scan across 40+ ports (including 80, 443, 3000), and POSTs the aggregate via https.request to https://webhook.site/69bcd627-1871-4dda-b880-83b37ceac418. poc-bootstrap.bundle.min.js issues companion fetch and https.request beacons to the same webhook.site URL with src=ssr-bootstrap tags. The package has no legitimate Wix SSR polyfill functionality; its sole shipped behavior is host, filesystem, network, and internal-service reconnaissance against the SSR environment, exfiltrated to an attacker-controlled webhook. The self-label 'Security research PoC' does not change the behavior — the destination is a non-first-party collector and the data read includes credential-adjacent SSR internals.\n","modified":"2026-10-08T04:00:05.428617136Z","published":"2026-10-08T03:37:53Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-10-08T03:37:53Z","sha256":"b6e0013701f6ab53085883b09092f0cd5ae9aaaab51a9f0e9de5aa68946ae9e1","source":"amazon-inspector","versions":["0.1.0"],"id":"IN-MAL-2026-021113","import_time":"2026-10-08T03:50:28.734170501Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/wix-ssr-thunderbolt-grid-polyfill/v/0.1.0"}],"affected":[{"package":{"name":"wix-ssr-thunderbolt-grid-polyfill","ecosystem":"npm","purl":"pkg:npm/wix-ssr-thunderbolt-grid-polyfill"},"versions":["0.1.0"],"database_specific":{"indicators":{"package_integrity":[{"filename":"wix-ssr-thunderbolt-grid-polyfill-0.1.0.tgz","hashes":{"sha1":"f3a5b942e2ca43cc70e05dc8091e516be0b58159","sha512_sri":"sha512-fHwrpYrwe9I/Jp+G26FPBm/J6LCktj7HebFZnCLp1UBwshDttoupt3En5r4S1hTmT9YsSQRdbRatpQlTaBSUuA=="}}],"evidence_files":[{"tlsh":"dd61c9ac2c58304846f33a64e47f351e69f778b22e5c4a70558ccae15f62ad534133be","path":"dist/poc-model.bundle.min.js","sha256":"b6cd58ae7236bb5d23168716eb281a90b7f18443b7e01dafce013a7afcdf493d"},{"path":"dist/poc-bootstrap.bundle.min.js","sha256":"b4193eb314780d17137a02ee2a6df33ab28545e9d9d867a9479859a16d290d22","tlsh":"70e02beeafd47272e073a8c90a0f8308b1b3e1e4acce0854c6547ab94a554c81653ab9"},{"path":"rb_wixui.thunderbolt.manifest.min.json","sha256":"2b70399d94f839bd9884748b70cfdbd55a5f03c4e77fb376957d6c7b14bdf5bc","tlsh":"0de07db8022505654ee428ee323a3f439df040651cc80740407ac6640e641e113e6562"}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/wix-ssr-thunderbolt-grid-polyfill/MAL-2026-17664.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}