Mistral denies a new security breach, but the code for sale looks a lot like the May leak
- The seller claims to be offering the full Mistral AI source code and says the company was breached again after the May 2026 attack.
- Mistral says an investigation found no evidence of new unauthorized access, but has not indicated whether the listed code is genuine.
- No customer data has appeared in the samples analyzed and no one has shown files created after the May incident.
A seller on a cybercrime forum says French giant Mistral AI has been hacked again and is offering what they call the company’s entire source code for sale.
The September 16, 2026 post by an account using the handle “mrwho” consists of a listing titled “mistral.ai source code for sale” on an English-language cybercrime forum, according to The CyberSec Guru, which prices the material in Monero only before attempting to direct potential buyers to Session or Telegram.
The Mistral AI team itself has refuted this, stating that it has “found no evidence to support this claim.”
Latest videos ofTechnologyRadar
It’s not the first PR issue centered around the Mistral hack.
The previous Mistral hacking incident is indisputable: in May 2026, the Mini Shai-Hulud supply chain campaign, attributed to the TeamPCP group, spread from compromised TanStack packages to hundreds of npm and PyPI projects.
Mistral’s own security advisory, MAI-2026-002, says that an automated worm caused compromised versions of its SDKs to be published for a few hours on May 11 and 12, and that an affected developer device was involved. Microsoft Threat Intelligence discovered that a poisoned Mistral AI Python package obtained a second-stage credential stealer that allowed the attack to exploit users.
Mistral went further in his statements to journalists than in his warning. said beepcomputer that the attackers had compromised a codebase management system and “contaminated some of our SDK packages for a brief period,” while insisting that hosted services, managed user data, and research and test environments were intact. He also said HackRead that only certain non-core repositories were accessed.
Meanwhile, TeamPCP advertised approximately 450 repositories, around 5 GB in total, for $25,000, and threatened to get rid of them for free if no buyers appeared within a week. Therefore, it can be argued that this could be the same dump being remarketed by a different account, and that the seller’s profile is already suspicious.
The cybersecurity guru noted that the account joined in September 2026 and had four posts and a reputation score of 30, despite showing a top-level “GOD User” ranking. That profile could fit a budding scam, but as the outlet noted, it could also fit a broker acting as a front for someone else or a newly created alias.
HackRead posted 24 sample repository names from the May TeamPCP release. FrenchBreaches, which examined the tree of 339 files that mrwho shared in September, lists several of the same names. At least four of them appear in both: mistral-inference-private, mistral-inference-internal, mistral-finetune-internal, and mistral-common-internal.
This makes it difficult to say whether the alleged ‘hack’ is just a replay of an existing dump from the previous Mistral breach or a second successful hacking attempt. However, there is a simple test: if the September files contain commits, files or credentials dated after May 12, or secrets that were still valid after the Mistral cleanup, the seller’s claim of a second violation gains real weight. If everything is before the May incident, it is a resale, which is embarrassing for Mistral, but not a new security breach.
Of course, locating the files or examining them would involve paying the ransom in cryptocurrency, as required by what could potentially be a scam in the making – a tremendous leap of faith for an account that was created earlier this month, making it essentially a lottery ticket, at best, for any security researcher trying to take a closer look.
Follow TechRadar on Google News and add us as a preferred source to receive news, reviews and opinions from our experts in your feeds.
Post Comment