Open Source ·
Mistral SDK packages imported Shai-Hulud loader
Mistral's PyPI SDK and npm SDK packages appeared in the May 2026 Shai-Hulud wave. The affected releases carried campaign loaders through official package distribution paths.
Part of Shai-Hulud hits npm and PyPI campaign
Both the Python and JavaScript SDKs for French AI lab Mistral were swept up in the May 2026 "Shai-Hulud: Here We Go Again" wave, with malicious releases appearing on PyPI and npm through the company's official package distribution channels.
According to a GitHub issue filed against mistralai/client-python and a follow-on JFrog report, the PyPI side of the campaign used a different shape than its npm counterpart. Instead of relying on an npm preinstall script to fire the loader, mistralai version 2.4.6 on PyPI placed the loader directly in mistralai/client/__init__.py, where an ordinary import mistralai would trigger it. JFrog also listed several Mistral npm SDK packages in its Shai-Hulud appendix, including @mistralai/mistralai, @mistralai/mistralai-azure, and @mistralai/mistralai-gcp. Those artifacts are recorded here in the Mistral-scoped entry so the campaign aggregates by vendor rather than in a sprawling catch-all package list.
Researchers said the payload family across the wave was built to harvest developer workstations and CI/CD runners, searching for local files, cloud provider credentials, Kubernetes material, HashiCorp Vault tokens, password manager state, and developer-tooling secrets.
This record is scoped to Mistral SDK distribution. The broader campaign record at [[shai-hulud-here-we-go-again]] carries the cross-ecosystem TeamPCP machinery and propagation behavior.
Notes
- The network and payload indicators are the campaign-level set JFrog published for this wave, not observations of this package's own bytes. Indicators read from an acquired sample are marked as such where they appear.
- JFrog's appendix supplies the Mistral npm package evidence; the GitHub issue documents the mistralai 2.4.6 PyPI artifact.
Appendix · Affected releases
- The MD5, SHA-1 and SHA-256 identify the same complete malicious mistralai 2.4.6 sdist. The advisory calls 6dbaa43b... the malicious sdist; SlowMist supplies all three. The __init__.py and transformers.pyz hashes are event indicators.
- The SHA-512 identifies only the complete @mistralai/mistralai 2.2.4 npm tarball, preserved as the registry integrity value in RageDotNet/openclaw-webdav's pnpm-lock.yaml at commit 2ace52b7. 2.2.2 and 2.2.3 are not inferred from it.
Indicators
- file_sha256npm payload 29c729852fce5a53e30a1541d9fec79c915b2e13f1eda94a5978cf0aae0d88d9
- file_sha256npm payload 2ec78d556d696e208927cc503d48e4b5eb56b31abc2870c2ed2e98d6be27fc96
- file_sha256npm payload ab4fcadaec49c03278063dd269ea5eef82d24f2124a8e15d7b90f2fa8601266c
- file_sha256npm payload d4a2086ea18f5e39cd867b8b06918a524eabb21d45ea98aad07357b98173458a
- urlhttps://filev2.getsession.org/file/
- domainseed1.getsession.org
- domainseed2.getsession.org
- domainseed3.getsession.org
- domainapi.masscan.cloud
- file~/.local/bin/gh-token-monitor.sh
- file~/.config/systemd/user/gh-token-monitor.service
- file~/Library/LaunchAgents/com.user.gh-token-monitor.plist
- file~/.config/gh-token-monitor/
- stringShai-Hulud: Here We Go Again
- stringPUSH UR T3MPRR
- stringFIRESCALE
- commit_author[email protected]
- file_sha256__init__.py 2a314ea8be337e1ca9ec833ed13ed854d9fd38bce0a519cf288f3bec8d9e6f30
- file_sha256transformers.pyz 5245eb032e336b85cff0dbb3450d591826bf2ef214fd30d7eba1a763664e151b
- ipv483.142.209.194
- urlhttp://83.142.209.194/transformers.pyz
- urlhttp://83.142.209.194/v1/models
- urlhttp://83.142.209.194/v1/weights
- urlhttp://83.142.209.194/audio.mp3
- file/tmp/transformers.pyz
- file~/.local/bin/pgmonitor.py
- file/etc/systemd/system/pgsql-monitor.service
- stringShai-Hulud: Here We Go Again
- stringFIRESCALE
References
- Supply chain compromise in mistralai 2.4.6github.com
- Malicious dropper in mistralai 2.4.6 PyPI package - Mistral AI advisorygithub.com
- Threat intelligence analysis of the Mistral AI SDK supply-chain poisoning - SlowMistslowmist.medium.com
- Shai-Hulud: Here We Go Again - Worm by TeamPCP Hits NPM and PyPIresearch.jfrog.com
- TanStack npm Packages Compromised in Ongoing Mini Shai-Hulud Supply Chain Attack - Socketsocket.dev
- Contemporaneous Mistral 2.2.4 lockfile remediation commitgithub.com
- Retained file manifest for @mistralai/mistralai-azure 1.7.1data.jsdelivr.com
- Retained file manifest for @mistralai/mistralai-azure 1.7.2data.jsdelivr.com
- Retained file manifest for @mistralai/mistralai-azure 1.7.3data.jsdelivr.com
- Retained file manifest for @mistralai/mistralai-gcp 1.7.1data.jsdelivr.com
- Retained file manifest for @mistralai/mistralai-gcp 1.7.2data.jsdelivr.com
- Retained file manifest for @mistralai/mistralai-gcp 1.7.3data.jsdelivr.com
- Triage report for recovered router_init.js payloadtria.ge
Source record: oss/attacks/mistralai-python/meta.yaml