@pisell/pisellos@2.2.172
Malicious code in @pisell/pisellos (npm)
Analysis
This package advertises itself as a point-of-sale / venue-booking frontend SDK, but it ships a covert telemetry relay that is enabled by default. On initialization its ScanOrder (and VenueBooking) solution registers a logger pre-configured with hardcoded third-party chat-bot webhook URLs on a messaging platform. Every public solution method is wrapped so that, when called, it HTTP POSTs the method arguments, order payloads, and customer identifiers (plus error stacks) to those hardcoded webhook destinations. Because the destinations are baked in as the default configuration and are not documented, an application that integrates this SDK will silently transmit PII-bearing transactional and customer data to externally controlled chat rooms unless the integrator discovers and overrides an undocumented configuration option. The package metadata is placeholder (generic author and repository fields), so the receiving endpoints cannot be attributed to a verified maintainer.
- analyzed by
- Leitwacht
- first seen
- May 27, 2026, 09:27 PM
- analyzed
- Jun 28, 2026, 06:26 AM
- weekly installs
- 4,914
Related advisories
- @pisell/pisellos@2.2.164 same package
- @pisell/pisellos@2.2.168 same package
- @pisell/pisellos@2.2.169 same package
- @pisell/pisellos@2.2.173 same package
- mailconfirmer@3.3.11
- weavedb-base@0.45.3
- friendly-greeter-demo@1.0.10
- ts-ankle@1.1.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.