LWA-2026-0035 MAL-2026-4417 ↗ confirmed malware

@pisell/pisellos@2.2.169

Malicious code in @pisell/pisellos (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

Critical maintainer_change finding: publisher email changed from [account] (corporate domain) to [account] (personal QQ email). This is a classic account takeover indicator - corporate to personal email transition with lifecycle hooks present (prepublishOnly). Package is a booking/solution library (~7.7MB) with no obvious token-theft markers in investigation, but the maintainer change pattern itself is high-risk and cannot be dismissed without verifying the legitimacy of the email change. Requires human review to confirm whether this is an authorized maintainer transition or a compromised account.

analyzed by
Leitwacht
first seen
May 26, 2026, 02:25 PM
analyzed
May 26, 2026, 06:36 PM
weekly installs
4,914

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.