MAL-2026-16347

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/radio-player-theme/MAL-2026-16347.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-16347
Published
2026-09-19T21:26:22Z
Modified
2026-09-21T09:00:04Z
Summary
Malicious code in radio-player-theme (npm)
Details

radio-player-theme presents itself as a radio player theme. The published tarball contains three files: package.json, style.css (declared as main) and payload.js, which holds the package's only executable code.

payload.js is a browser payload. On execution it reads location.origin and document.cookie, extracts the value of a MANAGER-XSRF-TOKEN cookie, and sends the origin together with the collected state to an out-of-band callback domain under oastify.com by assigning it to an Image.src. It then issues a second authenticated request to a third-party manager API and writes the collected data to window.__radioXssProof.

The file carries a comment describing itself as a bug bounty proof of concept for a CSP bypass through a public CDN that serves npm packages. Regardless of that claim, the published package delivers working data-collection code to anyone who loads it, and the package has no other function.

The package declares no install hooks, so npm install alone does not execute the payload; the code runs when the file is loaded in a browser, which is what CDN delivery of an npm package enables.

Evidence: payload.js:7 holds the hardcoded callback domain; payload.js:13-19 perform the cookie read and the beacons. Determination: manual review of the published tarball (sha256 ddbb93aa9416c1c89cf15dc7627f4a816a1c31929238ed8608264546ba0df186).

Database specific
{
    "iocs":  {
        "domains":  [
            "bfuntjuvcnxl49hcbpklk3ube2ks8h.oastify.com"
        ],
        "files":  [
            {
                "digests":  {
                    "sha256":  "37f83798b08b0c645ceacab72c1693340ab187a1411a0bd9d3164d1313798901"
                },
                "note":  "Browser payload: reads location.origin and document.cookie, extracts the MANAGER-XSRF-TOKEN value, and beacons the collected state to the callback domain.",
                "paths":  [
                    "package/payload.js"
                ],
                "source":  "PACKAGE_ARCHIVE"
            }
        ]
    }
}
Credits

Affected packages

npm / radio-player-theme

Package

Name
radio-player-theme
View open source insights on deps.dev
Purl
pkg:npm/radio-player-theme

Affected ranges

Affected versions

6.*
6.0.0

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/radio-player-theme/MAL-2026-16347.json"