LWA-2026-0036 MAL-2026-4417 ↗ confirmed malware

@pisell/pisellos@2.2.173

Malicious code in @pisell/pisellos (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

Critical maintainer_change finding: email changed from [account] (personal qq[.]com account) to [account] (corporate domain). Package has prepublishOnly lifecycle hook that runs 'npm run build' (father build). No token-theft markers found. Package appears to be legitimate booking/checkout solution SDK. However, maintainer_change + lifecycle hook is a known account-takeover attack pattern; cannot confidently rule out compromise without verifying publisher identity and repository legitimacy. Recommend human review to confirm this is a legitimate corporate migration vs. account takeover.

analyzed by
Leitwacht
first seen
May 26, 2026, 02:25 PM
analyzed
May 26, 2026, 06:36 PM
weekly installs
4,914

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.