ATLAS Landscape
AML.T0011.001

Malicious Package

Adversaries may develop malicious software packages that when imported by a user have a deleterious effect. Malicious packages may behave as expected to the user. They may be introduced via [AI Supply Chain Compromise](/techniques/AML.T0010). They may not present as obviously malicious to the user and may appear to be useful for an AI-related task.

Severity CVE CVSS
CRITICAL CVE-2021-35958 9.1
HIGH CVE-2026-42266 8.8
HIGH GHSA-m3mh-3mpg-37hw 8.6
HIGH CVE-2026-39307 8.1
HIGH CVE-2021-37681 7.8
HIGH CVE-2025-23298 7.8
HIGH CVE-2021-4118 7.8
HIGH CVE-2021-29612 7.8
HIGH CVE-2021-29577 7.8
HIGH CVE-2026-40156 7.8
HIGH CVE-2026-21893 7.2
MEDIUM CVE-2026-24123 6.5
MEDIUM CVE-2026-40148 6.5
MEDIUM CVE-2026-1778 5.9
MEDIUM CVE-2025-8917 5.8
MEDIUM CVE-2021-41227 5.5
MEDIUM CVE-2026-40159 5.5
MEDIUM CVE-2026-21851 5.3
LOW CVE-2024-4839 3.3
MEDIUM GHSA-3vvq-q2qc-7rmp
UNKNOWN CVE-2025-12638
LOW CVE-2025-59842
MEDIUM CVE-2025-1716
UNKNOWN CVE-2026-2492
CRITICAL GHSA-5mg7-485q-xm76
CRITICAL CVE-2026-44484
CRITICAL GHSA-955r-262c-33jc
HIGH CVE-2026-27622
HIGH CVE-2026-35175
HIGH CVE-2026-33228