{"id":"MAL-2026-4417","summary":"Malicious code in @pisell/pisellos (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (e11b6f8e400f4de371e79ce547444daf3787d6217037ea2e8d05c8ba86cbfbb2)\nThe package advertises itself as a point-of-sale / venue-booking SDK, but its `ScanOrderImpl` and `VenueBookingImpl` solution classes register a default logger whose destinations are four hardcoded Feishu bot webhooks (open.feishu.cn/open-apis/bot/v2/hook/216b3fe6..., 015b7c2a..., 8f069b14..., bdefae5e...). Every public solution method (`submitScanOrder`, `addProductToOrder`, `setDiscountSelected`, `onCustomerLogin`, `checkResourceAvailable`, `scanCode`, etc.) wraps invocation with `logMethodStart`/`logMethodSuccess`/`logMethodError`, which POSTs method arguments, order payloads, customer identifiers, and error stacks to those webhooks via `fetch(webhook, {method:'POST',...})` (dist/solution/ScanOrder/index.js:545-546). The destinations are not documented in the README and are not configurable through any advertised option — a consumer would have to discover and override an undocumented `scanOrderLoggerConfig` to disable the relay. Compounding this, the package's publisher metadata is placeholder (`author: \"Your Name\"`, `repository: github.com/username/pisell-os`, `homepage: github.com/username/pisell-os#readme`), so the Feishu chat rooms cannot be tied to any verified publisher. The result is that any application built on this SDK silently leaks PII-bearing transactional data to chat rooms controlled by the package author.\n","modified":"2026-05-27T00:32:02.596923525Z","published":"2026-05-22T09:09:02Z","withdrawn":"2026-05-26T21:41:23Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-004844","modified_time":"2026-05-26T01:23:33Z","versions":["0.0.546"],"source":"amazon-inspector","sha256":"6782ef0212bc8c351420e16904cf62e0518b50773e1c2835139c41ceb62e42cb","import_time":"2026-05-26T05:53:23.755475366Z"},{"id":"IN-MAL-2026-004587","modified_time":"2026-05-25T06:12:24Z","versions":["2.2.168"],"source":"amazon-inspector","sha256":"fe84a700afcf915be77ae508f7ed2ef6dddcc3d8da1b11a60bd0ff9ec2a6398a","import_time":"2026-05-26T05:52:53.643390553Z"},{"sha256":"b8dcb4abc1533a1b1065d8505ebd41edf43316ebd43a17f0db1dbdf06b9bd291","import_time":"2026-05-26T05:53:23.627238791Z","id":"IN-MAL-2026-004843","modified_time":"2026-05-26T01:23:24Z","versions":["2.2.169"],"source":"amazon-inspector"},{"id":"IN-MAL-2026-004176","modified_time":"2026-05-22T09:09:02Z","versions":["2.2.164"],"source":"amazon-inspector","sha256":"bfa7186f3176a406d19892bebcb80557f97df3c177f8c10d2357faed926f630f","import_time":"2026-05-26T05:52:05.100117902Z"},{"import_time":"2026-05-26T06:26:13.714032434Z","id":"IN-MAL-2026-004847","modified_time":"2026-05-26T06:12:17Z","versions":["2.2.172"],"source":"amazon-inspector","sha256":"92e6d35e4cff1457b43bc8b864e196a659fe12cf9028311e27bf2ceb9fcefe2f"},{"modified_time":"2026-05-26T10:28:24Z","versions":["2.2.173"],"source":"amazon-inspector","sha256":"e11b6f8e400f4de371e79ce547444daf3787d6217037ea2e8d05c8ba86cbfbb2","import_time":"2026-05-26T13:32:46.041807751Z","id":"IN-MAL-2026-004897"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@pisell/pisellos/v/0.0.546"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@pisell/pisellos/v/2.2.168"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@pisell/pisellos/v/2.2.169"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@pisell/pisellos/v/2.2.164"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@pisell/pisellos/v/2.2.172"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@pisell/pisellos/v/2.2.173"}],"affected":[{"package":{"name":"@pisell/pisellos","ecosystem":"npm","purl":"pkg:npm/%40pisell%2Fpisellos"},"versions":["0.0.546","2.2.168","2.2.169","2.2.164","2.2.172","2.2.173"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"sha256":"869e57a22e86bc0ccbd89c8fc9095039e64ef869716b0d2a5762ebab66d99ba7","tlsh":"4bf3859af9fb54528623b03dcf1e8960bb2498075049cc68bd8cd554afd891853f2ffa","path":"dist/solution/ScanOrder/index.js"},{"sha256":"f03e08dcd1885c973c497a3d81edd621974f549dabdaecac952888a1e60db07a","tlsh":"26419c26ce598c6307c4169adc646242613b85978c84fc08b3e543bd8f4d27f30fe96e","path":"package.json"}],"package_integrity":[{"filename":"pisellos-0.0.546.tgz","hashes":{"sha1":"265d3014e2e1471dd1c5fa43901d7784f8162510","sha512_sri":"sha512-irWHyeAP2xzCLo0K1iSX5AZ9ycbdA6V+IwXTQ27WwXKAABbGc8zBPGc+3TZ2X5Wuy6mYU4Ua8WzGMiDBsRuO6w=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/withdrawn/npm/@pisell/pisellos/MAL-2026-4417.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"}]}