VDB

GCVE-110-OSM-2026-12515

GCVE-110-OSM-2026-12515
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published September 21, 2026
`radio-player-theme` presents itself as a radio player theme. The published tarball contains three files: `package.json`, `style.css` (declared as `main`) and `payload.js`, which holds the package's only executable code. `payload.js` is a browser payload. On execution it reads `location.origin` and `document.cookie`, extracts the value of a `MANAGER-XSRF-TOKEN` cookie, and sends the origin together with the collected state to an out-of-band callback domain under `oastify.com` by assigning it to an `Image.src`. It then issues a second authenticated request to a third-party manager API and writes the collected data to `window.__radioXssProof`. The file carries a comment describing itself as a bug bounty proof of concept for a CSP bypass through a public CDN that serves npm packages. Regardless of that claim, the published package delivers working data-collection code to anyone who loads it, and the package has no other function. The package declares no install hooks, so `npm install` alone does not execute the payload; the code runs when the file is loaded in a browser, which is what CDN delivery of an npm package enables. Evidence: `payload.js:7` holds the hardcoded callback domain; `payload.js:13-19` perform the cookie read and the beacons. Determination: manual review of the published tarball (sha256 `ddbb93aa9416c1c89cf15dc7627f4a816a1c31929238ed8608264546ba0df186`). ENTRY style.css (main: style.css) DESTINATION - 6 exfil (oast, custom-c2) (values recorded in verified_iocs) EXFIL - OAST/Interactsh Exfiltration in payload.js: "oastify.com" - Data Encoding for Exfiltration in payload.js: "encodeURIComponent(origin) + '&t=' + Date.now" - Suspicious Domain in payload.js: "oastify.com" PAYLOAD FILES payload.js

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknownradio-player-themeall (affected)

References

advisory
vendor

Browse GCVE Records

317 records in the GCVE database · Updated September 22, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›