Mistral AI confirms data breach as hackers threaten to leak 450 stolen code repositories

2 Sources

Share

TeamPCP hackers are auctioning nearly 5GB of stolen Mistral AI source code for $25,000 on the dark web, threatening to release everything free if no buyer emerges. The French AI company confirmed its SDK packages were contaminated through the Mini Shai-Hulud supply-chain attack but insists core systems and user data remain secure.

TeamPCP Targets Mistral AI Through Supply-Chain Attack

Mistral AI faces a significant data breach after the TeamPCP hacker group stole nearly 450 repositories containing approximately 5 gigabytes of internal source code. The hackers are now advertising the stolen data on the dark web for $25,000, threatening to leak everything for free if no buyer emerges within a week

1

. The French AI company, founded by former researchers from Google's DeepMind and Meta, confirmed the breach stemmed from a sophisticated software supply-chain attack known as Mini Shai-Hulud that compromised its codebase management system

2

.

Source: BleepingComputer

Source: BleepingComputer

How the Mini Shai-Hulud Attack Unfolded

The incident began when TeamPCP poisoned official packages from TanStack, a widely-used collection of free software for building user interfaces with over 177 million weekly downloads. By compromising TanStack npm packages through stolen CI/CD credentials and legitimate workflows, the attackers distributed infostealer malware that harvested developer credentials, cloud secrets, and SSH keys

2

. The attack spread to hundreds of other software projects on the npm and PyPI registries, including UiPath, Guardrails AI, and OpenSearch. Mistral AI stated that a developer device was impacted by the TanStack supply-chain attack, which allowed hackers to contaminate some of the company's SDK packages for a brief period

1

.

What Data Was Compromised in the Breach

TeamPCP claims the stolen repositories contain internal source code that Mistral AI uses for training, fine-tuning, benchmarking, model delivery, and inference in experiments and future projects related to AI model development

1

. However, Mistral AI's forensic investigation determined that the impacted data was not part of the core code repositories. The company emphasized that its hosted services, managed user data, and research and testing environments were not compromised

1

. The hackers threaten to leak all stolen materials on forums if they cannot secure a buyer, with the asking price remaining flexible and open to negotiation

2

.

Broader Impact on AI Industry Security

The Mistral AI breach is not an isolated incident. OpenAI also confirmed that the TanStack supply-chain attack impacted systems of two employees who had access to a limited subset of internal source code repositories. A small set of credentials was stolen, though OpenAI found no evidence they were used in additional attacks. In response, OpenAI rotated exposed code-signing certificates and warned macOS users to update their desktop apps before June 12 or face potential launch failures

1

. The incident highlights growing vulnerabilities in software development pipelines across the AI sector, where compromised developer tools can cascade into widespread security breaches affecting multiple organizations simultaneously.

Source: TechRadar

Source: TechRadar

Today's Top Stories

TheOutpost.ai

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

Instagram logo
LinkedIn logo
Youtube logo
© 2026 TheOutpost.AI All rights reserved