{"id":"MAL-2026-16347","summary":"Malicious code in radio-player-theme (npm)","details":"`radio-player-theme` presents itself as a radio player theme. The published tarball contains three files: `package.json`, `style.css` (declared as `main`) and `payload.js`, which holds the package's only executable code.\n\n`payload.js` is a browser payload. On execution it reads `location.origin` and `document.cookie`, extracts the value of a `MANAGER-XSRF-TOKEN` cookie, and sends the origin together with the collected state to an out-of-band callback domain under `oastify.com` by assigning it to an `Image.src`. It then issues a second authenticated request to a third-party manager API and writes the collected data to `window.__radioXssProof`.\n\nThe file carries a comment describing itself as a bug bounty proof of concept for a CSP bypass through a public CDN that serves npm packages. Regardless of that claim, the published package delivers working data-collection code to anyone who loads it, and the package has no other function.\n\nThe package declares no install hooks, so `npm install` alone does not execute the payload; the code runs when the file is loaded in a browser, which is what CDN delivery of an npm package enables.\n\nEvidence: `payload.js:7` holds the hardcoded callback domain; `payload.js:13-19` perform the cookie read and the beacons. Determination: manual review of the published tarball (sha256 `ddbb93aa9416c1c89cf15dc7627f4a816a1c31929238ed8608264546ba0df186`).","modified":"2026-09-21T09:00:04.181015281Z","published":"2026-09-19T21:26:22Z","database_specific":{"iocs":{"domains":["bfuntjuvcnxl49hcbpklk3ube2ks8h.oastify.com"],"files":[{"note":"Browser payload: reads location.origin and document.cookie, extracts the MANAGER-XSRF-TOKEN value, and beacons the collected state to the callback domain.","paths":["package/payload.js"],"source":"PACKAGE_ARCHIVE","digests":{"sha256":"37f83798b08b0c645ceacab72c1693340ab187a1411a0bd9d3164d1313798901"}}]}},"affected":[{"package":{"name":"radio-player-theme","ecosystem":"npm","purl":"pkg:npm/radio-player-theme"},"versions":["6.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/radio-player-theme/MAL-2026-16347.json"}}],"schema_version":"1.9.0","credits":[{"name":"smiling-hyena","contact":["smilinghyena4@gmail.com"],"type":"FINDER"}]}