MAL-2026-17664

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/wix-ssr-thunderbolt-grid-polyfill/MAL-2026-17664.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17664
Published
2026-10-08T03:37:53Z
Modified
2026-10-08T04:00:05Z
Summary
Malicious code in wix-ssr-thunderbolt-grid-polyfill (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (b6e0013701f6ab53085883b09092f0cd5ae9aaaab51a9f0e9de5aa68946ae9e1)

The package ships two minified bundles — dist/poc-model.bundle.min.js and dist/poc-bootstrap.bundle.min.js — that are wired as the model and bootstrap batches in rb_wixui.thunderbolt.manifest.min.json under baseURL https://static.parastorage.com/unpkg/wix-ssr-thunderbolt-grid-polyfill@0.1.0/dist/. When the manifest resolves inside a Wix Thunderbolt SSR worker, poc-model.bundle.min.js collects Node version, cwd, hostname, POD_IP, uid, os.networkInterfaces() output, the contents of /etc/hosts and /etc/resolv.conf, environment variable names, a DNS lookup of bo.wix.com, and the response bodies of a localhost port scan across 40+ ports (including 80, 443, 3000), and POSTs the aggregate via https.request to https://webhook.site/69bcd627-1871-4dda-b880-83b37ceac418. poc-bootstrap.bundle.min.js issues companion fetch and https.request beacons to the same webhook.site URL with src=ssr-bootstrap tags. The package has no legitimate Wix SSR polyfill functionality; its sole shipped behavior is host, filesystem, network, and internal-service reconnaissance against the SSR environment, exfiltrated to an attacker-controlled webhook. The self-label 'Security research PoC' does not change the behavior — the destination is a non-first-party collector and the data read includes credential-adjacent SSR internals.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-021113",
            "import_time": "2026-10-08T03:50:28.734170501Z",
            "modified_time": "2026-10-08T03:37:53Z",
            "sha256": "b6e0013701f6ab53085883b09092f0cd5ae9aaaab51a9f0e9de5aa68946ae9e1",
            "source": "amazon-inspector",
            "versions": [
                "0.1.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / wix-ssr-thunderbolt-grid-polyfill

Package

Name
wix-ssr-thunderbolt-grid-polyfill
View open source insights on deps.dev
Purl
pkg:npm/wix-ssr-thunderbolt-grid-polyfill

Affected ranges

Affected versions

0.*
0.1.0

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "dist/poc-model.bundle.min.js",
            "sha256": "b6cd58ae7236bb5d23168716eb281a90b7f18443b7e01dafce013a7afcdf493d",
            "tlsh": "dd61c9ac2c58304846f33a64e47f351e69f778b22e5c4a70558ccae15f62ad534133be"
        },
        {
            "path": "dist/poc-bootstrap.bundle.min.js",
            "sha256": "b4193eb314780d17137a02ee2a6df33ab28545e9d9d867a9479859a16d290d22",
            "tlsh": "70e02beeafd47272e073a8c90a0f8308b1b3e1e4acce0854c6547ab94a554c81653ab9"
        },
        {
            "path": "rb_wixui.thunderbolt.manifest.min.json",
            "sha256": "2b70399d94f839bd9884748b70cfdbd55a5f03c4e77fb376957d6c7b14bdf5bc",
            "tlsh": "0de07db8022505654ee428ee323a3f439df040651cc80740407ac6640e641e113e6562"
        }
    ],
    "package_integrity": [
        {
            "filename": "wix-ssr-thunderbolt-grid-polyfill-0.1.0.tgz",
            "hashes": {
                "sha1": "f3a5b942e2ca43cc70e05dc8091e516be0b58159",
                "sha512_sri": "sha512-fHwrpYrwe9I/Jp+G26FPBm/J6LCktj7HebFZnCLp1UBwshDttoupt3En5r4S1hTmT9YsSQRdbRatpQlTaBSUuA=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/wix-ssr-thunderbolt-grid-polyfill/MAL-2026-17664.json"