Compromised Mistral AI and TanStack packages may have exposed GitHub, cloud and CI/CD credentials in 'mini Shai Hulud' malware infection — supply-chain campaign spreads across npm and AI developer ecosystems like wildfire
Source
Published
TL;DR
AI GeneratedMicrosoft is investigating a compromise of the mistralai PyPI package, where attackers injected malicious code that automatically executed on import, downloaded a secondary payload, and launched malware on Linux systems. The compromised package contained code that silently downloaded a file and executed it in the background, potentially stealing credentials and executing destructive commands. This incident is part of the broader "Mini Shai-Hulud" software supply-chain campaign affecting npm and AI developer ecosystems. Additionally, security firm Aikido warned of compromised TanStack JavaScript packages and Mistral npm SDK packages in separate attacks, urging developers to rotate credentials if affected. The incidents highlight the increasing targeting of developer infrastructure, emphasizing the importance of securing high-value credentials in modern development environments.