radio-player-theme@6.0.0
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 5:32 AM UTC
OSV ID
MAL-2026-16347
Ecosystem
npm
Summary
radio-player-theme@6.0.0 ships static browser assets (payload.js and a CSS file) whose content is a proof-of-concept CSS/XSS injection chain targeting a third-party service (manager.infomaniak.com), exfiltrating an origin string and an XSRF cookie preview to an Interactsh collaborator subdomain under oastify.com. The package declares no npm lifecycle scripts (preinstall/install/postinstall/prepare) and its main entry points at style.css, so nothing runs on npm install or on require(). The payload only has effect if the CSS/JS is loaded inside a victim's browser via the described injection chain against the third-party target, not against the developer who installs the package.
Source: amazon-inspector (6d9e0f0ee96d95fb59c2b3cfb30cfad6e32db8112eab806c63eda8f703e43d12)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.