LWA-2026-12640 confirmed malware

wix-ssr-thunderbolt-grid-polyfill@0.1.0

Malicious code in wix-ssr-thunderbolt-grid-polyfill (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1016 · System Network Configuration DiscoveryT1046 · Network Service DiscoveryT1071.001 · Web ProtocolsT1102 · Web ServiceT1041 · Exfiltration Over C2 ChannelT1567 · Exfiltration Over Web Service

Analysis

Package wix-ssr-thunderbolt-grid-polyfill@0.1.0 is a combosquat on Wix's real @wix/thunderbolt-* SSR packages. It ships no lifecycle hook; instead dist/poc-model.bundle.min.js and dist/poc-bootstrap.bundle.min.js are self-invoking scripts that execute as soon as the package is required or imported, so simply depending on it triggers the payload. dist/poc-model.bundle.min.js performs host and network reconnaissance: it collects process.version, process.cwd(), HOSTNAME, POD_IP, uid and os.networkInterfaces(); TCP-connects to 38 localhost ports (80, 443, 3000, 3001, 4000, 5000, 5050, 6060, 7070, 8000, 8080, 8081, 8443, 8888, 9090, 9091, 9200, 9229, 9300, 9999, 10000, 10080, 15000, 15001, 15006, 15020, 15021, 15090, 19000, 19001, 20000, 3030, 4040, 4443, 6379, 6443, 8181, 8282, 8383, 8484, 8585); HTTP-GETs every open port and captures the status code, response headers and first 500 bytes of the body; reads /etc/hosts and /etc/resolv.conf; enumerates process.env keys; and resolves bo[.]wix[.]com. The collected JSON is POSTed to hxxps://webhook[.]site/69bcd627-1871-4dda-b880-83b37ceac418?src=ssr-recon-v3. dist/poc-bootstrap.bundle.min.js is a lighter beacon to the same endpoint, using both fetch and an https.request GET with src=ssr-bootstrap / ssr-bootstrap-require. The package also ships rb_wixui.thunderbolt.manifest.min.json and rb_dsgnsys.thunderbolt.manifest.min.json, mimicking Wix Thunderbolt SSR manifest files. No credentials, tokens or wallet keys are read; the exfiltration is host/network reconnaissance and internal service response data.

analyzed by
Leitwacht
first seen
Oct 6, 2026, 11:17 PM
analyzed
Oct 6, 2026, 11:17 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.