Open Source ·

Mistral SDK packages imported Shai-Hulud loader

Mistral's PyPI SDK and npm SDK packages appeared in the May 2026 Shai-Hulud wave. The affected releases carried campaign loaders through official package distribution paths.

Part of Shai-Hulud hits npm and PyPI campaign

Both the Python and JavaScript SDKs for French AI lab Mistral were swept up in the May 2026 "Shai-Hulud: Here We Go Again" wave, with malicious releases appearing on PyPI and npm through the company's official package distribution channels.

According to a GitHub issue filed against mistralai/client-python and a follow-on JFrog report, the PyPI side of the campaign used a different shape than its npm counterpart. Instead of relying on an npm preinstall script to fire the loader, mistralai version 2.4.6 on PyPI placed the loader directly in mistralai/client/__init__.py, where an ordinary import mistralai would trigger it. JFrog also listed several Mistral npm SDK packages in its Shai-Hulud appendix, including @mistralai/mistralai, @mistralai/mistralai-azure, and @mistralai/mistralai-gcp. Those artifacts are recorded here in the Mistral-scoped entry so the campaign aggregates by vendor rather than in a sprawling catch-all package list.

Researchers said the payload family across the wave was built to harvest developer workstations and CI/CD runners, searching for local files, cloud provider credentials, Kubernetes material, HashiCorp Vault tokens, password manager state, and developer-tooling secrets.

This record is scoped to Mistral SDK distribution. The broader campaign record at [[shai-hulud-here-we-go-again]] carries the cross-ecosystem TeamPCP machinery and propagation behavior.

Notes

  • The network and payload indicators are the campaign-level set JFrog published for this wave, not observations of this package's own bytes. They identify the wave's infrastructure and persistence, and are recorded here so each affected distribution surface carries them. Where a record also lists indicators read from an acquired sample, those are marked as such.
  • JFrog's appendix supplies the Mistral npm package evidence; the GitHub issue documents the mistralai 2.4.6 PyPI artifact.

Appendix · Affected releases

mistralai pypi
2.4.6 sha256 2a314ea8…8d9e6f30 download unavailable
  • The MD5, SHA-1, and SHA-256 identify the same complete malicious mistralai 2.4.6 source distribution. The project advisory calls 6dbaa43b... the malicious sdist, while SlowMist supplies all three digests. The __init__.py and transformers.pyz hashes remain at event indicator scope and are not archive checksums.
2.2.4 no sample yet
2.2.3 no sample yet
2.2.2 no sample yet
  • The SHA-512 identifies only the complete @mistralai/mistralai 2.2.4 npm tarball. It is the registry-generated integrity value preserved in RageDotNet/openclaw-webdav's pnpm-lock.yaml at parent commit 2ace52b7e4f4f146713a0bff7d4cd76c2e37ce23, before the incident-response commit pinned the dependency to 2.2.1 after npm removed 2.2.4. Whole-archive hashes for 2.2.2 and 2.2.3 remain unavailable and are not inferred from this value.

Indicators

  • file_sha256npm payload 29c729852fce5a53e30a1541d9fec79c915b2e13f1eda94a5978cf0aae0d88d9
  • file_sha256npm payload 2ec78d556d696e208927cc503d48e4b5eb56b31abc2870c2ed2e98d6be27fc96
  • file_sha256npm payload ab4fcadaec49c03278063dd269ea5eef82d24f2124a8e15d7b90f2fa8601266c
  • file_sha256npm payload d4a2086ea18f5e39cd867b8b06918a524eabb21d45ea98aad07357b98173458a
  • urlhttps://filev2.getsession.org/file/
  • domainseed1.getsession.org
  • domainseed2.getsession.org
  • domainseed3.getsession.org
  • domainapi.masscan.cloud
  • file~/.local/bin/gh-token-monitor.sh
  • file~/.config/systemd/user/gh-token-monitor.service
  • file~/Library/LaunchAgents/com.user.gh-token-monitor.plist
  • file~/.config/gh-token-monitor/
  • stringShai-Hulud: Here We Go Again
  • stringPUSH UR T3MPRR
  • stringFIRESCALE
  • commit_authorclaude@users.noreply.github.com
  • file_sha256__init__.py 2a314ea8be337e1ca9ec833ed13ed854d9fd38bce0a519cf288f3bec8d9e6f30
  • file_sha256transformers.pyz 5245eb032e336b85cff0dbb3450d591826bf2ef214fd30d7eba1a763664e151b
  • ipv483.142.209.194
  • urlhttp://83.142.209.194/transformers.pyz
  • urlhttp://83.142.209.194/v1/models
  • urlhttp://83.142.209.194/v1/weights
  • urlhttp://83.142.209.194/audio.mp3
  • file/tmp/transformers.pyz
  • file~/.local/bin/pgmonitor.py
  • file/etc/systemd/system/pgsql-monitor.service
  • stringShai-Hulud: Here We Go Again
  • stringFIRESCALE

References

  1. Supply chain compromise in mistralai 2.4.6github.com
  2. Malicious dropper in mistralai 2.4.6 PyPI package - Mistral AI advisorygithub.com
  3. Threat intelligence analysis of the Mistral AI SDK supply-chain poisoning - SlowMistslowmist.medium.com
  4. Shai-Hulud: Here We Go Again - Worm by TeamPCP Hits NPM and PyPIresearch.jfrog.com
  5. TanStack npm Packages Compromised in Ongoing Mini Shai-Hulud Supply Chain Attack - Socketsocket.dev
  6. Contemporaneous Mistral 2.2.4 lockfile remediation commitgithub.com
  7. Retained file manifest for @mistralai/mistralai-azure 1.7.1data.jsdelivr.com
  8. Retained file manifest for @mistralai/mistralai-azure 1.7.2data.jsdelivr.com
  9. Retained file manifest for @mistralai/mistralai-azure 1.7.3data.jsdelivr.com
  10. Retained file manifest for @mistralai/mistralai-gcp 1.7.1data.jsdelivr.com
  11. Retained file manifest for @mistralai/mistralai-gcp 1.7.2data.jsdelivr.com
  12. Retained file manifest for @mistralai/mistralai-gcp 1.7.3data.jsdelivr.com
  13. Triage report for recovered router_init.js payloadtria.ge

Source record: oss/attacks/mistralai-python/meta.yaml