YWH bug bounty CSS injection live-C2 proof — stage 3 exfil
Applying this stylesheet to the targeted manager page causes browser background-image requests to a player API and exfiltration-marking endpoints. A CSS attribute selector distinguishes a specific UUID.
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
style.cssView on unpkgThe stylesheet makes a background request when a targeted share input is present.
style.cssView on unpkg · L9A selector tests for a specific player UUID and sends a distinct confirmation request.
style.cssView on unpkg · L14The stylesheet requests a specific player configuration API path when applied.
style.cssView on unpkg · L19The manifest describes a CSS injection live command-and-control proof with exfiltration.
package.jsonView on unpkg · L2This report applies to radio-player-theme@3.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
style.cssView on unpkgThe stylesheet makes a background request when a targeted share input is present.
style.cssView on unpkg · L9A selector tests for a specific player UUID and sends a distinct confirmation request.
style.cssView on unpkg · L14The stylesheet requests a specific player configuration API path when applied.
style.cssView on unpkg · L19The manifest describes a CSS injection live command-and-control proof with exfiltration.
package.jsonView on unpkg · L2