MEDIUMSupply Chain
Global

Hijacked npm Package Attempts to Deliver PolinRider-Linked RAT

·Source: Sonatype (Maven/npm)

Updated:

Executive Summary

<img src="https://www.sonatype.com/hubfs/blog_npm_hijack2.jpg" alt="Image with large text at center "npm package hijack" and the Sonatype company name above it." class="hs-featured-image" style="width:auto !important

Analysis

Attackers do not need to wait fo r a CVE whe n they can publish directly into the build.

Indicators of Compromise (4)

URL (3)
https://www.sonatype.com/blog/hijacked-npm-package-attempts-to-deliver-polinrider-linked-rat
https://www.sonatype.com/hubfs/blog_npm_hijack2.jpg
https://www.sonatype.com/security-advisories
Domain (1)
www.sonatype.com
Source Attribution

Originally published by Sonatype (Maven/npm) on May 21, 2026.

Related Threats