Loading npm security reports…
OpenSSF/OSV advisory MAL-2026-16347 confirms this npm version as malicious. `radio-player-theme` presents itself as a radio player theme. The published tarball contains three files: `package.json`, `style.css` (declared as `main`) and `payload.js`, which holds the package's only executable code.
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
style.cssView on unpkgThis report applies to radio-player-theme@2.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
style.cssView on unpkg