# sonatype-2026-003277

Malicious Packages - Thu May 21 2026 \[PolinRider\] \[Dropper\]

Published May 21, 2026

[help.sonatype.com](https://help.sonatype.com/en/sonatype-malware-data.html) [OSV](https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2026-5546.json)

CVSS Score: High 8.7

## Security Details

### Components Impacted

### Sonatype Research

#### sonatype-2026-003277 Security Details

**CVE ID:** sonatype-2026-003277  
**CVE Description:** Malicious Packages - Thu May 21 2026 \[PolinRider\] \[Dropper\]  
**Published:** May 21, 2026  
**CVSS Score & Severity:** 8.7 High  
**CVSS Vector:** CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N  
**EPSS Score:** 0%

### Malware

**KEV Status:** Not in KEV Catalog: No known exploits

### Affected Ecosystems

**Source:** Sonatype

### References

[help.sonatype.com](https://help.sonatype.com/en/sonatype-malware-data.html) THIRD_PARTY  
[OSV](https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2026-5546.json) THIRD_PARTY
