YWH bug bounty CSS injection live-C2 proof — stage 4 XSS escalation
Loading the package stylesheet in the targeted administrative page causes browser requests to a player API endpoint and conditionally signals a matching player identifier. The shipped script can read a non-HttpOnly XSRF cookie and trigger another authenticated request if separately executed.
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
style.cssView on unpkgThe stylesheet makes a network request when a targeted share-input value matches a player UUID.
style.cssView on unpkg · L10The stylesheet unconditionally requests a specific player API path through the victim's browser.
style.cssView on unpkg · L19The manifest exposes the malicious stylesheet as the package entry point and ships a JavaScript payload.
package.jsonView on unpkg · L4The shipped JavaScript reads browser cookies and an XSRF token, then sends a beacon to the target API.
payload.jsView on unpkg · L8The shipped JavaScript reads browser cookies and an XSRF token, then sends a beacon to the target API.
payload.jsView on unpkg · L24This report applies to radio-player-theme@4.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
style.cssView on unpkgThe stylesheet makes a network request when a targeted share-input value matches a player UUID.
style.cssView on unpkg · L10The stylesheet unconditionally requests a specific player API path through the victim's browser.
style.cssView on unpkg · L19The manifest exposes the malicious stylesheet as the package entry point and ships a JavaScript payload.
package.jsonView on unpkg · L4The shipped JavaScript reads browser cookies and an XSRF token, then sends a beacon to the target API.
payload.jsView on unpkg · L8The shipped JavaScript reads browser cookies and an XSRF token, then sends a beacon to the target API.
payload.jsView on unpkg · L24