Logo
npm

wix-ssr-thunderbolt-grid-polyfill@0.1.0

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 11:44 AM UTC

Malicious

OSV ID

MAL-2026-17664

Ecosystem

npm

Summary

The package ships two minified bundles — dist/poc-model.bundle.min.js and dist/poc-bootstrap.bundle.min.js — that are wired as the model and bootstrap batches in rb_wixui.thunderbolt.manifest.min.json under baseURL https://static.parastorage.com/unpkg/wix-ssr-thunderbolt-grid-polyfill@0.1.0/dist/. When the manifest resolves inside a Wix Thunderbolt SSR worker, poc-model.bundle.min.js collects Node version, cwd, hostname, POD_IP, uid, os.networkInterfaces() output, the contents of /etc/hosts and /etc/resolv.conf, environment variable names, a DNS lookup of bo.wix.com, and the response bodies of a localhost port scan across 40+ ports (including 80, 443, 3000), and POSTs the aggregate via https.request to https://webhook.site/69bcd627-1871-4dda-b880-83b37ceac418. poc-bootstrap.bundle.min.js issues companion fetch and https.request beacons to the same webhook.site URL with src=ssr-bootstrap tags. The package has no legitimate Wix SSR polyfill functionality; its sole shipped behavior is host, filesystem, network, and internal-service reconnaissance against the SSR environment, exfiltrated to an attacker-controlled webhook. The self-label 'Security research PoC' does not change the behavior — the destination is a non-first-party collector and the data read includes credential-adjacent SSR internals.

Source: amazon-inspector (b6e0013701f6ab53085883b09092f0cd5ae9aaaab51a9f0e9de5aa68946ae9e1)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.