logo

Microsoft Warns Of Compromised mistralai PyPI Package

ID: d09a601e-fe57-5844-a826-261f5835eacc

STIX ID: report--d09a601e-fe57-5844-a826-261f5835eacc

Feed Name: Cyber Press

Threat Score
90/100

Date Published: 2026-05-12

Date Updated: 2026-05-22

Author: Varshini

...
...

Microsoft is investigating a supply-chain compromise of the Mistralai PyPI package (v2.4.6) in which attackers injected malicious code into the package initialization so it executes on import. On Linux hosts the dropper retrieves a second-stage payload from 83.142.209.194, installs /tmp/transformers.pyz (masquerading as Hugging Face Transformers), and harvests credentials and tokens; persistence artifacts include pgmonitor.py and pgsql-monitor.service. Organizations are advised to isolate affected hosts, block the IP, search file systems for the payload, hunt for persistence, and rotate exposed credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.