BotBeat
...
← Back

> ▌

Mistral AIMistral AI
UPDATEMistral AI2026-05-11

Mistral AI's NPM Package Compromised in Shai Hulud Supply Chain Attack

Key Takeaways

  • ▸Mistral AI's @mistralai/mistralai npm package (v2.2.4) was compromised by the Shai Hulud worm supply chain attack
  • ▸The attack is self-spreading and specifically targets the npm ecosystem, affecting multiple packages
  • ▸Developers who installed the compromised version face potential execution of malicious code in their environments
Source:
Hacker Newshttps://github.com/mistralai/client-ts/issues/217↗

Summary

Mistral AI's official TypeScript SDK package (@mistralai/mistralai) on NPM has been compromised as part of the "Shai Hulud worm," a self-spreading supply chain attack targeting the npm ecosystem. Version 2.2.4 of the package was confirmed to be affected, exposing developers who installed the compromised version to malicious code injection through the npm package manager.

The Shai Hulud worm is a sophisticated supply chain attack that spreads automatically by injecting malicious code into popular npm packages. Developers using the affected version of Mistral AI's client library would have had unauthorized code executed in their environments during installation or runtime. This is particularly concerning given the widespread use of such SDKs across development organizations building AI applications.

  • This incident highlights the vulnerability of open source dependency chains and the importance of package verification
MLOps & InfrastructureCybersecurityPrivacy & DataOpen Source

More from Mistral AI

Mistral AIMistral AI
RESEARCH

Mistral's Le Chat Repeats State-Sponsored Disinformation Half the Time, NewsGuard Audit Finds

2026-06-16
Mistral AIMistral AI
PARTNERSHIP

Mistral AI Deploys Team to Kyiv for Defense Partnership

2026-06-16
Mistral AIMistral AI
INDUSTRY REPORT

Mistral AI Positions as Europe's Full-Stack AI Provider at Paris Summit

2026-05-29

Comments

Suggested

KlueKlue
POLICY & REGULATION

Klue OAuth Breach Expands: Icarus Hackers Claim Attack, Multiple Tech Firms Affected

2026-06-20
InceptionInception
PRODUCT LAUNCH

Inception Unveils Mercury 2: Parallel-Token Diffusion Models Reshape LLM Performance Economics

2026-06-20
AikidoAikido
PRODUCT LAUNCH

Aikido Launches Code Audit: AI-Powered Tool to Find Complex Logic Vulnerabilities Before They Ship

2026-06-19
← Back to news
© 2026 BotBeat
AboutPrivacy PolicyTerms of ServiceContact Us