Breaking 16:22 Allociné calls Charles de Gaulle a 'controversial hero': a statement that sparks debate 16:18 European Union: Six Countries Call for a Windfall Tax on Oil Company Profits 15:44 2027 Presidential Election: Matthieu Pigasse Embraces Common Ground with LFI Against Manuel Bompard 15:27 US Open 2026: Serena Williams and Carlos Alcaraz Team Up for Highly Anticipated Mixed Doubles 15:10 Spain: Heavy Rains Injure Seven and Lead to Evacuation of a Campsite in Catalonia 14:53 Summer Hits of 2026: From Mauvais Djo to Aya Nakamura, the Songs That Defined the Season 14:05 Boxing: Two-Time World Champion Zolani Tete Shot Dead at 38 14:00 Venezuela: Opposition Deputy Under Investigation After Proposal for Dollarization 14:00 France recalls 260,000 condoms over serious safety concerns 13:45 Five football stars surrounded by speculation about their religious beliefs 13:42 Ukraine: Macron condemns Russian strikes and promises new interceptor missiles 13:40 Greece: Six Suspected Members of Rouvikonas Sought After an 'Anti-Zionist Patrol' 13:29 Road Tragedy in Ireland: Five Teenagers Killed in Deadly Viral Challenge 13:27 Busan Launches Arctic Route to Bypass Middle Eastern Crisis 13:25 TikTok agrees to pay $400 million to settle U.S. child privacy case 13:10 Apple pays $17 billion in taxes in Ireland in a single year 12:54 Gianni Infantino under pressure: Concacaf urges him to avoid junior tournament in the Dominican Republic 12:54 Gianni Infantino under pressure: Concacaf urges him to avoid junior tournament in the Dominican Republic 12:50 Alex Lanier reaches the world final and writes a new chapter in French badminton 12:47 UN secretary-general race enters a new phase as Rodriguez-Birkett gains ground 12:30 From exploring the unknown to solving Earth’s challenges: Space enters the age of biotechnology 12:12 European stocks rebound after longest losing streak since 2023 11:50 More than 660 million barrels of oil cross the Strait of Hormuz with US military support 11:41 Morocco strengthens its attack capabilities with AH-64E Apache helicopters 11:32 China launches its largest vehicle recall campaign as safety rules tighten 11:28 International sports tribunal overturns Senegal football federation decision on presidential election 11:15 US economy accelerates to strongest pace in more than four years 11:08 Democrats consider congressional investigations into Trump after midterm elections 11:00 Morocco and the United States deepen defense ties through new military equipment deliveries 10:46 Prince Harry and Elton John Ordered to Pay £9.5 Million to Daily Mail 10:41 China challenges the United States in a new AI race driven by cost and scale 10:21 Tawfik Bentayeb joins Anderlecht for four seasons 10:20 UK warns of an unusually strong El Niño that could drive record temperatures 10:19 Mali: Two Former Wagner Combatants Released After Two Years in Captivity 10:05 Washington prepares $725 million payment to the United Nations amid growing financial pressure 09:47 Las Vegas: Alisa Goods' Disappearance Surrounded by Suspicious Messages and Demands for Bitcoins 09:45 Europe records more than 30,000 excess deaths during a summer of extreme heat 09:36 Nigeria: A Jihadist Attack Claims Lives and Leaves Many Missing During Friday Prayers 09:34 Myanmar: 14 dead after airstrike on monastery 09:25 Belgium nominates Hans Kluge for WHO director-general 09:09 UN report highlights two Moroccan human rights initiatives as global best practices 08:47 Tangier Med warns of peak return traffic during Marhaba 2026 08:32 Moroccan phosphate industry faces cadmium challenge while strengthening its position in Europe 08:15 FIFA imposes heavy sanctions on Argentina following 2026 World Cup final incidents

Hackers claim sale of Mistral AI source code after supply chain attack

Thursday 14 May 2026 - 14:44
By: Dakir Madiha
Hackers claim sale of Mistral AI source code after supply chain attack

Cybercriminals linked to the TeamPCP group are claiming to sell around 5 gigabytes of alleged internal source code repositories belonging to Mistral AI for $25,000, escalating concerns over a broader software supply chain campaign that recently targeted multiple artificial intelligence and open source projects.

The offer appeared on a hacker forum and included threats to publicly release the data within a week if no buyer emerged. Threat intelligence services flagged the post on May 14, only days after TeamPCP’s “Mini Shai Hulud” operation compromised public SDK packages linked to Mistral AI on the npm and PyPI registries. The attackers claimed the leaked material included roughly 450 repositories associated with the namespaces “mistralai” and “mistral-solutions.”

Repository names listed in the advertisement suggested access to sensitive internal development projects. The alleged cache reportedly included systems connected to model inference, fine tuning infrastructure, benchmarking tools, cloud deployment environments and chatbot security evaluation frameworks. One repository title referenced a project labeled “pfizer-rfp-2025,” raising additional concerns about potential enterprise or commercial collaborations exposed in the breach.

Cybersecurity intelligence firm VECERT described the incident as a critical threat and warned that exposed repositories could contain hard coded credentials, API keys and infrastructure secrets. Analysts urged Mistral AI to immediately rotate authentication keys and review all development environments connected to the compromised projects. Independent security researchers, however, have not verified whether the repositories genuinely originate from Mistral AI’s internal systems.

Mistral AI issued a security advisory on May 12 acknowledging that some SDK packages had been compromised during the wider TanStack supply chain attack. The company stated that the breach involved an infected developer device and insisted there was no evidence that its internal infrastructure had been penetrated. According to the company, the malicious npm packages were available for only a short period between May 11 and May 12 before removal.

The broader campaign exposed weaknesses in modern open source software distribution systems. On May 11, TeamPCP launched coordinated attacks against more than 170 packages across npm and PyPI, targeting organizations including UiPath, OpenSearch and Guardrails AI. Investigators said the group exploited vulnerabilities in GitHub Actions workflows to distribute malicious software packages carrying legitimate cryptographic signatures, making them appear authentic to developers.

Security researchers from Palo Alto Networks Unit 42 previously linked TeamPCP to attacks involving Aqua Security’s Trivy scanner and Bitwarden’s CLI package. Researchers at Wiz later found that a flaw in the malware payload prevented credential theft from functioning correctly in some npm packages linked to Mistral AI and UiPath, although Linux systems using the compromised PyPI package remained vulnerable.

Uncertainty continues to surround the authenticity of the alleged repository sale. No public evidence has confirmed whether the hackers possess valuable intellectual property or whether the claims are part of a pressure campaign designed to exploit attention surrounding the recent supply chain compromises.


  • Fajr
  • Sunrise
  • Dhuhr
  • Asr
  • Maghrib
  • Isha

Read more

This website, walaw.press, uses cookies to provide you with a good browsing experience and to continuously improve our services. By continuing to browse this site, you agree to the use of these cookies.