LWA-2026-0033 MAL-2026-4417 ↗ confirmed malware

@pisell/pisellos@2.2.164

Malicious code in @pisell/pisellos (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

Critical maintainer_change finding: publisher email changed from [account] (corporate domain) to [account] (free QQ email provider). This is a classic account takeover/supply chain compromise pattern. Package has prepublishOnly lifecycle hook. While investigation showed no token-theft markers and the hook just runs build, the email change from corporate to free provider is highly suspicious and warrants human review. Cannot confidently dismiss.

analyzed by
Leitwacht
first seen
May 26, 2026, 02:25 PM
analyzed
May 26, 2026, 06:37 PM
weekly installs
4,914

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.