-= Per source details. Do not edit below this line.=-
The package ships two minified bundles — dist/poc-model.bundle.min.js and dist/poc-bootstrap.bundle.min.js — that are wired as the model and bootstrap batches in rb_wixui.thunderbolt.manifest.min.json under baseURL https://static.parastorage.com/unpkg/wix-ssr-thunderbolt-grid-polyfill@0.1.0/dist/. When the manifest resolves inside a Wix Thunderbolt SSR worker, poc-model.bundle.min.js collects Node version, cwd, hostname, POD_IP, uid, os.networkInterfaces() output, the contents of /etc/hosts and /etc/resolv.conf, environment variable names, a DNS lookup of bo.wix.com, and the response bodies of a localhost port scan across 40+ ports (including 80, 443, 3000), and POSTs the aggregate via https.request to https://webhook.site/69bcd627-1871-4dda-b880-83b37ceac418. poc-bootstrap.bundle.min.js issues companion fetch and https.request beacons to the same webhook.site URL with src=ssr-bootstrap tags. The package has no legitimate Wix SSR polyfill functionality; its sole shipped behavior is host, filesystem, network, and internal-service reconnaissance against the SSR environment, exfiltrated to an attacker-controlled webhook. The self-label 'Security research PoC' does not change the behavior — the destination is a non-first-party collector and the data read includes credential-adjacent SSR internals.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-021113",
"import_time": "2026-10-08T03:50:28.734170501Z",
"modified_time": "2026-10-08T03:37:53Z",
"sha256": "b6e0013701f6ab53085883b09092f0cd5ae9aaaab51a9f0e9de5aa68946ae9e1",
"source": "amazon-inspector",
"versions": [
"0.1.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "dist/poc-model.bundle.min.js",
"sha256": "b6cd58ae7236bb5d23168716eb281a90b7f18443b7e01dafce013a7afcdf493d",
"tlsh": "dd61c9ac2c58304846f33a64e47f351e69f778b22e5c4a70558ccae15f62ad534133be"
},
{
"path": "dist/poc-bootstrap.bundle.min.js",
"sha256": "b4193eb314780d17137a02ee2a6df33ab28545e9d9d867a9479859a16d290d22",
"tlsh": "70e02beeafd47272e073a8c90a0f8308b1b3e1e4acce0854c6547ab94a554c81653ab9"
},
{
"path": "rb_wixui.thunderbolt.manifest.min.json",
"sha256": "2b70399d94f839bd9884748b70cfdbd55a5f03c4e77fb376957d6c7b14bdf5bc",
"tlsh": "0de07db8022505654ee428ee323a3f439df040651cc80740407ac6640e641e113e6562"
}
],
"package_integrity": [
{
"filename": "wix-ssr-thunderbolt-grid-polyfill-0.1.0.tgz",
"hashes": {
"sha1": "f3a5b942e2ca43cc70e05dc8091e516be0b58159",
"sha512_sri": "sha512-fHwrpYrwe9I/Jp+G26FPBm/J6LCktj7HebFZnCLp1UBwshDttoupt3En5r4S1hTmT9YsSQRdbRatpQlTaBSUuA=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/wix-ssr-thunderbolt-grid-polyfill/MAL-2026-17664.json"