@pisell/pisellos@2.2.164
Malicious code in @pisell/pisellos (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
Critical maintainer_change finding: publisher email changed from [account] (corporate domain) to [account] (free QQ email provider). This is a classic account takeover/supply chain compromise pattern. Package has prepublishOnly lifecycle hook. While investigation showed no token-theft markers and the hook just runs build, the email change from corporate to free provider is highly suspicious and warrants human review. Cannot confidently dismiss.
- analyzed by
- Leitwacht
- first seen
- May 26, 2026, 02:25 PM
- analyzed
- May 26, 2026, 06:37 PM
- weekly installs
- 4,914
Related advisories
- @pisell/pisellos@2.2.172 same package
- @pisell/pisellos@2.2.168 same package
- @pisell/pisellos@2.2.169 same package
- @pisell/pisellos@2.2.173 same package
- statist-browser-typed-client-fsi.cm.web@0.0.1
- statist-browser-typed-client-forge.informer.events@0.0.1
- statist-browser-typed-client-forge.front.metrics@0.0.1
- statist-browser-typed-client-eventea.spend.advisor@0.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.