Skip to content

Mistral AI Software Compromised by Malware

Malware Compromises Mistral AI Software via PyPI

  • Microsoft reported that attackers inserted malicious code into a Mistral AI software package distributed through PyPI.
  • The malware, disguised as transformers.pyz, stole credentials and could delete files on Linux systems in Israel or Iran.
  • Mistral confirmed involvement in a supply-chain attack linked to the TanStack security incident, affecting NPM and PyPI packages.
  • The attack is part of the broader “Shai-Hulud” campaign targeting software supply chains since September.

Microsoft advised isolating affected systems and replacing exposed credentials due to the attack’s potential impact on developer environments. The malware primarily targeted credential theft while avoiding Russian-language systems.

This incident highlights vulnerabilities in trusted software distribution platforms like PyPI and NPM, which are critical for developers worldwide. (Source)

Share