YWH bug bounty CSS injection live-C2 proof — stage 4 XSS escalation
The published theme files are a live browser payload. Applying style.css or loading payload.js steals session data and talks to an out-of-band host plus Infomaniak manager APIs.
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
style.cssView on unpkgstyle.css uses background-image, SVG fill, and @font-face urls to force authenticated GETs to Infomaniak manager APIs.
style.cssView on unpkg · L20CSS attribute selectors leak a share-input UUID to a C2 confirmation URL.
style.cssView on unpkg · L15Package metadata describes a live C2 XSS and CSS-injection payload, not a theme.
package.jsonView on unpkg · L2payload.js reads document cookies and the Infomaniak manager XSRF token, then beacons the page origin to an oastify collaborator.
payload.jsView on unpkg · L7payload.js also fires an authenticated image request to the Infomaniak manager API.
payload.jsView on unpkg · L16Comments present this as a jsdelivr CSP-bypass and CSS-injection delivery vector.
payload.jsView on unpkg · L1This report applies to radio-player-theme@6.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
style.cssView on unpkgstyle.css uses background-image, SVG fill, and @font-face urls to force authenticated GETs to Infomaniak manager APIs.
style.cssView on unpkg · L20CSS attribute selectors leak a share-input UUID to a C2 confirmation URL.
style.cssView on unpkg · L15Package metadata describes a live C2 XSS and CSS-injection payload, not a theme.
package.jsonView on unpkg · L2payload.js reads document cookies and the Infomaniak manager XSRF token, then beacons the page origin to an oastify collaborator.
payload.jsView on unpkg · L7payload.js also fires an authenticated image request to the Infomaniak manager API.
payload.jsView on unpkg · L16Comments present this as a jsdelivr CSP-bypass and CSS-injection delivery vector.
payload.jsView on unpkg · L1