Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

radio-player-themenpm

radio-player-theme is a confirmed malicious npm package (MAL-2026-16347) that steals credentials and exfiltrates sensitive data (malicious version 6.0.0). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in radio-player-theme (npm)

MAL-2026-16347
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall radio-player-theme

What this malware does

radio-player-theme presents itself as a radio player theme. The published tarball contains three files: package.json, style.css (declared as main) and payload.js, which holds the package's only executable code.

payload.js is a browser payload. On execution it reads location.origin and document.cookie, extracts the value of a MANAGER-XSRF-TOKEN cookie, and sends the origin together with the collected state to an out-of-band callback domain under oastify.com by assigning it to an Image.src. It then issues a second authenticated request to a third-party manager API and writes the collected data to window.__radioXssProof.

The file carries a comment describing itself as a bug bounty proof of concept for a CSP bypass through a public CDN that serves npm packages. Regardless of that claim, the published package delivers working data-collection code to anyone who loads it, and the package has no other function.

The package declares no install hooks, so npm install alone does not execute the payload; the code runs when the file is loaded in a browser, which is what CDN delivery of an npm package enables.

Evidence: payload.js:7 holds the hardcoded callback domain; payload.js:13-19 perform the cookie read and the beacons. Determination: manual review of the published tarball (sha256 ddbb93aa9416c1c89cf15dc7627f4a816a1c31929238ed8608264546ba0df186).

Malicious versions

1 flagged
6.0.0

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for radio-player-theme (version 6.0.0). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging radio-player-theme across your stack and pipelines.

  2. If you installed it — respond

    radio-player-theme is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If radio-player-theme was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks radio-player-theme before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. radio-player-theme on npm has been identified as a malicious package (version 6.0.0 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Credits

  • smiling-hyena · finder

Detect & block this

O3 blocks radio-player-theme-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

radio-player-theme (npm) malicious package — MAL-2026-16347 | O3 Security