VDB
GCVE-110-OSM-2026-12515
GCVE-110-OSM-2026-12515
Advisory PublishedCVSS 5.4/10
`radio-player-theme` presents itself as a radio player theme. The published tarball contains three files: `package.json`, `style.css` (declared as `main`) and `payload.js`, which holds the package's only executable code.
`payload.js` is a browser payload. On execution it reads `location.origin` and `document.cookie`, extracts the value of a `MANAGER-XSRF-TOKEN` cookie, and sends the origin together with the collected state to an out-of-band callback domain under `oastify.com` by assigning it to an `Image.src`. It then issues a second authenticated request to a third-party manager API and writes the collected data to `window.__radioXssProof`.
The file carries a comment describing itself as a bug bounty proof of concept for a CSP bypass through a public CDN that serves npm packages. Regardless of that claim, the published package delivers working data-collection code to anyone who loads it, and the package has no other function.
The package declares no install hooks, so `npm install` alone does not execute the payload; the code runs when the file is loaded in a browser, which is what CDN delivery of an npm package enables.
Evidence: `payload.js:7` holds the hardcoded callback domain; `payload.js:13-19` perform the cookie read and the beacons. Determination: manual review of the published tarball (sha256 `ddbb93aa9416c1c89cf15dc7627f4a816a1c31929238ed8608264546ba0df186`).
ENTRY
style.css (main: style.css)
DESTINATION
- 6 exfil (oast, custom-c2)
(values recorded in verified_iocs)
EXFIL
- OAST/Interactsh Exfiltration in payload.js: "oastify.com"
- Data Encoding for Exfiltration in payload.js: "encodeURIComponent(origin) + '&t=' + Date.now"
- Suspicious Domain in payload.js: "oastify.com"
PAYLOAD FILES
payload.js
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | radio-player-theme | all (affected) | — |
Aliases
Browse GCVE Records
317 records in the GCVE database · Updated September 22, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.