Attackers compromised the official Mistral AI Python package on PyPI along with hundreds of other widely-used developer packages, exposing GitHub tokens, cloudAttackers compromised the official Mistral AI Python package on PyPI along with hundreds of other widely-used developer packages, exposing GitHub tokens, cloud

Mistral AI and TanStack hit in supply chain attack with SLSA-attested malware

For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Attackers compromised the official Mistral AI Python package on PyPI along with hundreds of other widely-used developer packages, exposing GitHub tokens, cloud credentials, and password vaults across the AI and crypto developer ecosystem.

Microsoft Threat Intelligence said on May 11, it was investigating the mistralai PyPI package version 2.4.6 after discovering malicious code injected in mistralai/client/__init__.py that executed on import, downloading a secondary payload from 83.142.209.194 to /tmp/transformers.pyz and launching it on Linux systems.

Mistral AI and TanStack hit in supply chain attack with SLSA-attested malware

The filename impersonates Hugging Face’s widely used Transformers AI framework. The Mistral compromise is one piece of a coordinated campaign researchers are calling Mini Shai-Hulud.

Security platform SafeDep reported that the operation compromised over 170 packages and published 404 malicious versions between May 11 and 12.

The attack carries CVE-2026-45321 with a CVSS score of 9.6, rating it critical severity.

The SLSA provenance trust model just broke

What makes this attack structurally unprecedented: the malicious packages carried valid SLSA Build Level 3 provenance attestations.

SLSA provenance is a cryptographic certificate generated by Sigstore meant to verify that a package was built from a trusted source.

Snyk reported the TanStack attack is the first documented case of malicious npm packages with valid SLSA provenance, meaning attestation-based supply chain defenses are now demonstrably insufficient.

The attackers, identified as TeamPCP, chained three vulnerabilities: a pull_request_target workflow misconfiguration, GitHub Actions cache poisoning, and runtime memory extraction of an OIDC token from the GitHub Actions runner process.

The malicious commit was authored under a fabricated identity impersonating the Anthropic Claude GitHub App, prefixed with [skip ci] to suppress automated checks.

What the malware steals and how it spreads

As Cryptopolitan reported on the January 2026 Trust Wallet incident tied to $8.5 million in losses, the Shai-Hulud worm has been evolving across multiple waves since September 2025.

This latest variant adds password vault theft, with Wiz researchers documenting that the malware now targets 1Password and Bitwarden vaults alongside SSH keys, AWS and GCP credentials, Kubernetes service accounts, GitHub tokens, and npm publishing credentials.

The stealer exfiltrates via three redundant channels: a typosquat domain (git-tanstack.com), the decentralized Session messenger network, and Dune-themed GitHub repositories created with stolen tokens.

The malware exits if Russian language settings are detected. On systems geolocated to Israel or Iran, it introduces a 1-in-6 probability of executing recursive wipe (rm -rf /).

How Mistral and the broader ecosystem responded

Mistral published a security advisory on May 12 saying its core infrastructure was not compromised. The company traced the incident to a compromised developer device tied to the broader TanStack supply-chain campaign.

The mistralai==2.4.6 release was uploaded shortly after midnight UTC on May 12, before PyPI quarantined the project.

Compromised npm packages, including @mistralai/mistralai, @mistralai/mistralai-azure, and @mistralai/mistralai-gcp, were available for several hours before removal.

The cumulative weekly download volume of the compromised packages exceeds 518 million. @tanstack/react-router alone receives 12.7 million weekly downloads.

Developers who installed affected versions are advised to rotate cloud credentials, GitHub tokens, SSH keys, and exchange API keys, and inspect .claude/ and .vscode/ directories for persistence hooks.

If you're reading this, you’re already ahead. Stay there with our newsletter.

Market Opportunity
Gensyn Logo
Gensyn Price(AI)
$0.0254
$0.0254$0.0254
-2.15%
USD
Gensyn (AI) Live Price Chart

Get Covered, Share 1M USDT

Get Covered, Share 1M USDTGet Covered, Share 1M USDT

Higher VVIP tiers, higher compensation odds.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Covéa Chooses Shift Technology as Strategic Partner for Fraud and Risk Management

Covéa Chooses Shift Technology as Strategic Partner for Fraud and Risk Management

Covéa has selected Shift Technology as a long-term partner to support a consistent and shared view of risk from policy inception through to claims settlement The
Share
ffnews2026/04/02 07:00
One Of Frank Sinatra’s Most Famous Albums Is Back In The Spotlight

One Of Frank Sinatra’s Most Famous Albums Is Back In The Spotlight

The post One Of Frank Sinatra’s Most Famous Albums Is Back In The Spotlight appeared on BitcoinEthereumNews.com. Frank Sinatra’s The World We Knew returns to the Jazz Albums and Traditional Jazz Albums charts, showing continued demand for his timeless music. Frank Sinatra performs on his TV special Frank Sinatra: A Man and his Music Bettmann Archive These days on the Billboard charts, Frank Sinatra’s music can always be found on the jazz-specific rankings. While the art he created when he was still working was pop at the time, and later classified as traditional pop, there is no such list for the latter format in America, and so his throwback projects and cuts appear on jazz lists instead. It’s on those charts where Sinatra rebounds this week, and one of his popular projects returns not to one, but two tallies at the same time, helping him increase the total amount of real estate he owns at the moment. Frank Sinatra’s The World We Knew Returns Sinatra’s The World We Knew is a top performer again, if only on the jazz lists. That set rebounds to No. 15 on the Traditional Jazz Albums chart and comes in at No. 20 on the all-encompassing Jazz Albums ranking after not appearing on either roster just last frame. The World We Knew’s All-Time Highs The World We Knew returns close to its all-time peak on both of those rosters. Sinatra’s classic has peaked at No. 11 on the Traditional Jazz Albums chart, just missing out on becoming another top 10 for the crooner. The set climbed all the way to No. 15 on the Jazz Albums tally and has now spent just under two months on the rosters. Frank Sinatra’s Album With Classic Hits Sinatra released The World We Knew in the summer of 1967. The title track, which on the album is actually known as “The World We Knew (Over and…
Share
BitcoinEthereumNews2025/09/18 00:02
Not a loophole: Singapore AI export controls let China tap US AI legally

Not a loophole: Singapore AI export controls let China tap US AI legally

American AI technology is reaching Chinese tech giants through a route that US export controls were never designed to close: Singapore. The city-state sits outside
Share
The Cryptonomist2026/07/10 14:46

Record Ads, Stock Down 7%

Record Ads, Stock Down 7%Record Ads, Stock Down 7%

Jul 29: Meta earnings face the market's question.