LWA-2026-0034 MAL-2026-4417 ↗ confirmed malware

@pisell/pisellos@2.2.168

Malicious code in @pisell/pisellos (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

Critical maintainer_change finding: email changed from [account] to [account]. Package has prepublishOnly lifecycle hook (runs npm run build - benign). Investigation found no token-theft markers. The eval() usage in lib/plugins/window.js is legitimate - it's a mock browser setTimeout/setInterval implementation for a sandboxed environment SDK. Package appears to be a frontend modular SDK framework. However, repository URL uses generic 'username' placeholder (github[.]com/username/pisell-os), and I cannot independently verify the publisher identity transition. Given Critical severity and inability to fully confirm this is a legitimate corporate email migration vs. account takeover, recommending human review.

analyzed by
Leitwacht
first seen
May 26, 2026, 02:25 PM
analyzed
May 26, 2026, 06:37 PM
weekly installs
4,914

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.