PulseAugur
LIVE 01:00:13
tool · [2 sources] ·
1
tool

Malware infects Mistral AI, TanStack packages, stealing developer credentials

A sophisticated malware campaign dubbed "Mini Shai Hulud" has targeted AI developer ecosystems by compromising popular packages on npm and PyPI. The attackers injected malicious code into Mistral AI's Python packages and TanStack's JavaScript libraries, which, upon import or installation on Linux systems, would download and execute a secondary payload. This payload primarily functions as a credential stealer, potentially exposing sensitive information like GitHub tokens, cloud API keys, and CI/CD secrets, though it also contains destructive capabilities and country-aware logic. AI

Summary written by gemini-2.5-flash-lite from 2 sources. How we write summaries →

IMPACT Compromised AI development tools could lead to widespread credential theft and further supply-chain attacks within the AI ecosystem.

RANK_REASON Supply-chain attack on third-party packages used by AI developers.

Read on Tom's Hardware →

Malware infects Mistral AI, TanStack packages, stealing developer credentials

COVERAGE [2]

  1. Tom's Hardware TIER_1 · Etiido Uko ·

    Compromised Mistral AI and TanStack packages may have exposed GitHub, cloud and CI/CD credentials in 'mini Shai Hulud' malware infection — supply-chain campaign spreads across npm and AI developer ecosystems like wildfire

    Microsoft says attackers compromised the mistralai PyPI package with malware that executed on import, while researchers link related npm compromises affecting TanStack and Mistral SDKs to the broader “Mini Shai-Hulud” supply-chain campaign.

  2. Mastodon — fosstodon.org TIER_1 Português(PT) · [email protected] ·

    Massive attack hits Mistral AI, UiPath, and TanStack npm and PyPI packages 🔗 https://tugatech.com.pt/t83314-ataque-massivo-atinge-pacotes-npm-e-pypi-da-mistral

    Ataque massivo atinge pacotes npm e PyPI da Mistral AI, UiPath e TanStack 🔗 https:// tugatech.com.pt/t83314-ataque- massivo-atinge-pacotes-npm-e-pypi-da-mistral-ai-uipath-e-tanstack # ai # ataque # mistral