VDB
Sign up

MAL-2026-16347

Malicious code in radio-player-theme (npm)

Details

`radio-player-theme` presents itself as a radio player theme. The published tarball contains three files: `package.json`, `style.css` (declared as `main`) and `payload.js`, which holds the package's only executable code.

`payload.js` is a browser payload. On execution it reads `location.origin` and `document.cookie`, extracts the value of a `MANAGER-XSRF-TOKEN` cookie, and sends the origin together with the collected state to an out-of-band callback domain under `oastify.com` by assigning it to an `Image.src`. It then issues a second authenticated request to a third-party manager API and writes the collected data to `window.__radioXssProof`.

The file carries a comment describing itself as a bug bounty proof of concept for a CSP bypass through a public CDN that serves npm packages. Regardless of that claim, the published package delivers working data-collection code to anyone who loads it, and the package has no other function.

The package declares no install hooks, so `npm install` alone does not execute the payload; the code runs when the file is loaded in a browser, which is what CDN delivery of an npm package enables.

Evidence: `payload.js:7` holds the hardcoded callback domain; `payload.js:13-19` perform the cookie read and the beacons. Determination: manual review of the published tarball (sha256 `ddbb93aa9416c1c89cf15dc7627f4a816a1c31929238ed8608264546ba0df186`).

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/radio-player-theme

No fixed version published yet for radio-player-theme (npm). Pin to a known-safe version or switch to an alternative.