BotBeat
...
← Back

> ▌

Mistral AIMistral AI
UPDATEMistral AI2026-05-11

Mistral AI's NPM Package Compromised in Shai Hulud Supply Chain Attack

Key Takeaways

  • ▸Mistral AI's @mistralai/mistralai npm package (v2.2.4) was compromised by the Shai Hulud worm supply chain attack
  • ▸The attack is self-spreading and specifically targets the npm ecosystem, affecting multiple packages
  • ▸Developers who installed the compromised version face potential execution of malicious code in their environments
Source:
Hacker Newshttps://github.com/mistralai/client-ts/issues/217↗

Summary

Mistral AI's official TypeScript SDK package (@mistralai/mistralai) on NPM has been compromised as part of the "Shai Hulud worm," a self-spreading supply chain attack targeting the npm ecosystem. Version 2.2.4 of the package was confirmed to be affected, exposing developers who installed the compromised version to malicious code injection through the npm package manager.

The Shai Hulud worm is a sophisticated supply chain attack that spreads automatically by injecting malicious code into popular npm packages. Developers using the affected version of Mistral AI's client library would have had unauthorized code executed in their environments during installation or runtime. This is particularly concerning given the widespread use of such SDKs across development organizations building AI applications.

  • This incident highlights the vulnerability of open source dependency chains and the importance of package verification
MLOps & InfrastructureCybersecurityPrivacy & DataOpen Source

More from Mistral AI

Mistral AIMistral AI
INDUSTRY REPORT

Shai-Hulud Campaign Compromises 160+ npm and PyPI Packages with Valid Cryptographic Signatures

2026-05-12
Mistral AIMistral AI
INDUSTRY REPORT

Massive Coordinated Supply Chain Attack Compromises 170+ npm and 2 PyPI Packages, Including Mistral AI SDKs

2026-05-12
Mistral AIMistral AI
UPDATE

Mistral AI Python Package Compromised: Backdoor Detected in Version 2.4.6

2026-05-12

Comments

Suggested

AnthropicAnthropic
OPEN SOURCE

Anthropic Releases Prempti: Open-Source Guardrails for AI Coding Agents

2026-05-12
vlm-runvlm-run
OPEN SOURCE

mm-ctx: Open-Source Multimodal CLI Toolkit Brings Vision Capabilities to AI Agents

2026-05-12
AnthropicAnthropic
PRODUCT LAUNCH

Anthropic Unleashes Computer Use: Claude 3.5 Sonnet Now Controls Your Desktop

2026-05-12
← Back to news
© 2026 BotBeat
AboutPrivacy PolicyTerms of ServiceContact Us