Automatically translated.View original post

The hackers secretly inserted malware into the Mistral AI installation package.

The hackers secretly inserted malware into the Mistral AI installation package and tricked the victim into downloading it.

According to a report by the website, Emerge has mentioned the detection of a campaign in which hackers insert malware on an AI tool popular with developers like Mistral AI. This tool is available for download on the PyPI platform, a source of software to work with the Python language used by developers. According to a review by the Microsoft Threat Intelligence research team from Microsoft, the malware code hidden in the AI tool package is automatically run when it is detected on the Linux operating system, where the script downloads the second payload file called transformers.pyz. The research team identified it as a naming similar to the library of Hugging Face Transformers to perform the environment of software development and machine learning.

The research team determined that the malware was a malware type that stole data from the victim or an Infostealer that was primarily responsible for password theft and Token access to the developer's system. It also found that the malware was avoided on Russian-language machines, and in some cases if it was detected that the malware was running within the area of Israel or Iran, the malware would randomly delete files on the system. Therefore, the research team recommended that malware be separated from the company's network immediately, including address blocks associated with the malware, as well as changing the code. All passes. To secure internal information and limit potential damage.

In that attack, Mistral acknowledged that it was a supply chain attack, a result of which TanStack was attacked on a supply chain attack called "Shai-Hulud," which led to malware scripts being fielded on packages distributed through NPM and PyPI. At this time, the development team was dealing with the affected developers, while confirming that the infrastructure associated with Mistral AI was not compromised.

# Trending # Lemon 8 Howtoo # lemon 8 diary # mistral # freedomhack

1 day agoEdited to

... Read moreจากประสบการณ์การทำงานในวงการไอทีและการพัฒนาโปรแกรม พบว่าแคมเปญโจมตีผ่านซอฟต์แวร์โอเพนซอร์สและแพ็กเกจบนแพลตฟอร์มนิยม เช่น PyPI หรือ NPM เริ่มพบมากขึ้นเรื่อย ๆ โดยเฉพาะในกลุ่มเครื่องมือ AI และ Machine Learning ที่กำลังมาแรง กรณี Mistral AI ที่มีมัลแวร์แอบแฝงในแพ็กเกจและทำงานอัตโนมัติบนระบบ Linux ถือเป็นตัวอย่างที่ชี้ให้เห็นความเสี่ยงของการพึ่งพาโค้ดที่ได้มาจากแหล่งภายนอกโดยตรง ไฟล์มัลแวร์ตัวที่สองที่ชื่อ transformers.pyz ถูกตั้งชื่อให้เหมือนกับไลบรารีชื่อดังในวงการ ทำให้ยากสำหรับผู้พัฒนาที่เร่งทำงานภายใต้เวลาอันจำกัดที่จะสังเกตเห็นความผิดปกติ ที่น่าสนใจคือมัลแวร์นี้มีความสามารถตรวจจับสภาพแวดล้อมของระบบปฏิบัติการและหลีกเลี่ยงการทำงานบนเครื่องที่ใช้ภาษารัสเซีย รวมถึงมีพฤติกรรมทำลายไฟล์ในประเทศอิสราเอลและอิหร่าน ซึ่งสะท้อนถึงเป้าหมายที่มีความซับซ้อนและเจาะจงมากกว่าการโจมตีทั่วไป ในฐานะผู้ใช้งานหรือนักพัฒนา หากต้องดาวน์โหลดเครื่องมือหรือไลบรารีใด ๆ ก็ควรตรวจสอบความน่าเชื่อถือของแหล่งที่มาให้แน่ชัด รวมถึงใช้ซอฟต์แวร์ตรวจจับมัลแวร์ที่เหมาะสมบ่อย ๆ การแยกระบบที่ติดมัลแวร์ออกจากเครือข่ายทันทีและการเปลี่ยนรหัสผ่านทั้งหมดเป็นมาตรการพื้นฐานแต่สำคัญในการลดความเสียหาย สุดท้ายนี้ เหตุการณ์นี้ยังตอกย้ำถึงความสำคัญของการรักษาความปลอดภัยห่วงโซ่อุปทานซอฟต์แวร์ที่เป็นส่วนประกอบขนาดเล็กแต่มีผลกระทบเชิงลึกต่อทุกองค์กรและนักพัฒนาในวงกว้าง

Related posts

A young woman with long dark hair, wearing a pink satin shirt, smiles at the camera while sitting at a table. Overlay text reads: 'Tools and sites I use as a cybersecurity student to progress my skills and keep me interested in studying'.
A screenshot of 'The Hacker News' website, displaying various cybersecurity news articles from January 2025, including topics like vulnerabilities, malware, cyber espionage, and AI jailbreak methods. An ad for Zscaler and a banner for CIS Hardened Images are also visible.
A screenshot of the O'Reilly learning platform, showing various books and expert playlists related to AI, engineering, and data. Overlay text highlights the subscription cost ($50/month or $499/year) and its value for accessing books and live events.
Tools and sites I use as a cybersecurity student 🌸
#cybersecuritystudent #cybersecurity #techgirlie
LexiStudies

LexiStudies

107 likes

The image shows a phone screen displaying a 'Creating...' message with text claiming entities are 'hackers, trackers and child predators.' It includes a person surrounded by swirling energy and mentions Lilith, Satan, and Ra as parasitic beings.
The image displays a list of AI prompt suggestions, including 'Make me best friends with the Grim Reaper drinking boba tea,' which is circled. Below, text questions why befriending the Grim Reaper (Satan) is acceptable.
The image features a person with swirling energy and text stating, 'Can't create videos of prominent figures. Try something else instead.' It questions when Satan, Lilith, and Ra became prominent figures, describing them as disembodied beings preying on teens.
YouTube made Satan/Lilith/Ra (Demon Spirits) Prominent Figures #teen YouTube
I claim my protected emotional, mental, emotional, and digital space. All energetic loosh and currency stays with me, not those who prey upon it. *"I do not give, offer, or forfeit my crown to the dark forces who oppose me."* Those who steal will, with crafted weaved intentions div
Energy Frequency & Magic

Energy Frequency & Magic

0 likes

A laptop with a cloudy sky wallpaper and a white cup with a red logo. Text overlay reads: 'Free Websites That Saved My GPA AND MY SANITY Sharing So You Don't Struggle Too'.
A laptop screen displays Yahoo search results for 'Quizlet'. An overlay describes Quizlet as a free flashcard tool for memorizing terms, definitions, and formulas, making studying feel like a game.
A laptop screen displays Yahoo search results for 'Unriddle.ai'. An overlay describes Unriddle.ai as a free tool that breaks down notes, articles, or assignments to aid understanding of long readings.
Websites You NEED to Pass Your College Courses
Y’all college is hard enough without trying to figure everything out on your own 😩 So here’s my list of websites that actually helped me pass my classes like, these were in my survival kit. I’m not gatekeeping 🫶🏽 Quizlet When I needed to memorize terms FAST. I used it for flashcards, and the matc
Beauty

Beauty

285 likes

4 In demand Certificates You Need in 2025
Hey Career Girl, I know you want to start off the New Year on the right foot and a certificate is just the thing. Certificates can open the doors to new pathways in the career world that wouldn't have been opened before! Love this type of content? Follow and share! Need Interview P
Lauren|Career Girl

Lauren|Career Girl

164 likes

when ur attorney is on a roll
darkangel1984666

darkangel1984666

1 like

Blue jackets hockey is on the riseeeeeeee
peyton

peyton

1 like

A hand holds a pink iPhone with text 'Tech 101 For Beginners' and 'Tips to help Non-Tech Savvy Users,' accompanied by laptop and phone app icons, against a brick background.
A pink iPhone in its box, illustrating the tip to 'Keep Your Devices Updated' with text explaining why updates help and advising to enable automatic updates.
An iPhone screen displaying app icons and display settings, accompanying the tip to 'Use Strong, Unique Passwords' with reasons why and advice on using combinations and password managers.
Tech Hacks For Beginners 📲💻😬
I have some great tips for non-tech savvy tech users. I know these tips will help you learn your tech more quickly and effectively. 1. Keep Your Devices Updated Why It Helps: Updates often contain security patches and improvements that help your device run smoothly. Tip: Enable automatic updat
Joy 📚

Joy 📚

283 likes

A Fortnite character in a victory pose with a "Victory Royale" banner, overlaid with text "How I Improved My Fortnite Skills" and a "SWIPEZ" arrow, indicating the start of a guide.
Two Fortnite gameplay screenshots comparing graphics settings. The top shows high settings (Shadows ON, View Distance FAR), while the bottom shows low settings (Shadows OFF, View Distance NEAR) for improved visibility.
A Fortnite UI displaying accolades like "TWO TO ONE ODDS" for winning a Duos match solo, and "ONE MAN'S TREASURE" for using legendary weapons, alongside a first-person view of gameplay.
How I Improved My Fortnite Skills In 1 Season
Adjust Your Settings This is optional, your settings may already be perfect for your devices and your gameplay style. However, certain things in the game or your system can sometimes impact your gameplay. Fortnite takes a lot of processing power, so if you can relieve some of the load by adjusting
🌻ChromaGlitch

🌻ChromaGlitch

315 likes

Get hired or get refunded. The best way to get into the tech industry! #careeradvice #careerchange
Lizbeth | Lilies Bikinis

Lizbeth | Lilies Bikinis

0 likes

Taco Tuesday 🤯 Admin Abuse ⁉️ #stealabrainrot #robloxstealabrainrot #roblox #neoskittles
NeoSkittles

NeoSkittles

6 likes

Nice one boys
#cod #callofdutyp #codapartments #pvp #ashika #finalexfil #ashikapowerplant #almazrah #talkingshit #squad #dmz #gamer #sniper #headshot #longrange #headbussa #letthebodieshitthefloor #proxie #closecombat #closecombatfight #talkingshit #kamikazi #nomercy #nolovelost #groundhack #rocke
TheAuditor

TheAuditor

1 like

#stitch with @Steve-O’s Wild Ride! Podcast & @Drew On Spotify | what do you think? 🤔 I suggest checking out @The Hacking Games to support your kids! 💥 #videogames #onlinesafety #parentinghacks #momsoftiktokover30
Fareedah | Protect Kids Online

Fareedah | Protect Kids Online

5 likes

A monitor displays the Martin AI assistant dashboard with sections for to-dos, reminders, calendar, and chat, set on a desk with a keyboard and plant, illustrating the phrase "Say what you need, it gets it done."
The Martin AI assistant dashboard is shown, featuring to-dos, reminders, calendar, inbox, and a chat interface for sending schedules, emphasizing its ability to use voice commands for tasks like texting and setting reminders.
The Martin AI assistant dashboard displays to-dos, reminders, calendar, and an inbox with emails, highlighting its function to remember and track information across various platforms without repetition.
Your to-do list just got a personal manager
You know when you have too many tabs open in your brain? This app is like closing all of them... at once. Martin is your Al assistant that actually works like a real one. Need to text someone, forward notes, set reminders, or manage your day? Just tell Martin. It connects with your inbox,
Reverelia

Reverelia

366 likes

#yungblud
watch4hackers

watch4hackers

8 likes

The image shows a keyboard with a fingerprint icon, overlaid with "OUTSMART HACKERS" and "Secrets they don't want you to know," serving as the title for a guide on cybersecurity.
This image explains hackers use software to guess passwords and advises creating long passwords with a random mix of letters, numbers, and symbols to defend against such attacks.
The image warns that hackers try common passwords and advises users to defend themselves by avoiding easy words/phrases and not reusing passwords across different sites.
SECRETS Hackers DON’T Want You to Know!
After hackers got into my Facebook account and completely erased it, I dusted myself off and started a deep dive to understand why and how hackers work. The best way to protect yourself is to outsmart them. Here are 5 secrets Hackers DON'T want you to know! Share this with everyone! #lemon8pa
techgirljen

techgirljen

424 likes

A travel tip graphic advises using a VPN for security on public Wi-Fi, set against a blurred airport background. It features a profile picture of Bridgitte Monique, a Certified Travel Advisor, along with her contact information and Lemon8 handle.
Travel Tip of the Day
Follow for more travel advice and ideas. (I follow back 😉) #travelwithme2025 #traveltip #traveltipsandtricks #traveladvisor #exploretheworldwithme #lemon8travel
Bridgitte | Travel | Wellness

Bridgitte | Travel | Wellness

8 likes

BIG Holiday Costco Shop & Haul | Anchorage, Alaska
vanditsv

vanditsv

2 likes

Amen thanks Father God Jesus Christ God evening word and prayer devil's I rebuke you your childrens Morehouse parish sheriff department officers and Mike Stone Tubbs and hackers and Elon Musk and Donald Trump and Mark Zuckerberg and Randy Tappin and Christopher Thirdkill and IT and their countr
glentrump359

glentrump359

0 likes

Amen thanks Father God Jesus Christ God morning word and prayer devil's I rebuke you your childrens Morehouse parish sheriff department officers and Mike Stone Tubbs and hackers and Elon Musk and Donald Trump and Mark Zuckerberg and Randy Tappin and Christopher Thirdkill and IT and their countr
glentrump359

glentrump359

0 likes

SEPT WRAP UP PT 1.
september had me in a CHOKEHOLD y'all 😮‍💨 i read so much i have to break this into TWO PARTS 😂😂 • 47 books read (don't play with me •) • 19 new authors • multiple favorites that little binge had me blowing right past my 200 book goal, so you know i had to bump it up to 250 from messy d
LEXI 💓

LEXI 💓

33 likes

If you have the Samsung, you need to watch this and update your phone immediately 
Cybersecurity Girl

Cybersecurity Girl

49 likes

PSA PSA PSA ‼️ #fyp #hackers #facebook #scammers #viral
Kay’s House ✨

Kay’s House ✨

2 likes

Just An FYI This Is How So Many People are Getting Hacked!!! Plz Don’t Fall For Message Like These!!! it’s A Fake Account!!! #fakeaccount #hackers
MaryBell

MaryBell

2 likes

I wanted a real project I could actually show, not just talk about. So I used Atoms ⚛️ Check it out here: https://tinyurl.com/3xzc8xbe It feels like having a whole AI team helping me: 🔍 they do the deep research first 🏁 then Race Mode builds different versions so I can compare 👥 I just pick
emilie.studygram

emilie.studygram

19 likes

Instagram is sharing your exact location to all your followers Turn this off ASAP. #techtips #instagram #news #technews
Cybersecurity Girl

Cybersecurity Girl

200 likes

A 3D printed Baymax figure, made from rose gold/orange silky PLA, stands on a dark surface. It features black eyes and a shiny gold heart on its chest, showcasing a textured, knit-like appearance.
Baymax 3D Print!
Just a little colorful Baymax I printed for my wife. I used Matterhackers silky rose gold PLA for the body. #3dprinting #fyp #foryoupage #disney @
PrintsWithChris

PrintsWithChris

3 likes

How Hackers Could Crash 20 Million Devices! #podcast #hacker #hack #fyp
ShawRyanClips

ShawRyanClips

2 likes

Tcg
#TCG available at @brooklynvideogames . #Pokemon #OnePiece #MTG #Yugioh and more…
ArcadeBrooklyn

ArcadeBrooklyn

3 likes

⚠️ The Hidden Dangers of Public Wi-Fi Free Wi-Fi feels convenient, but it can be a trap. Hackers can create what’s called an “evil twin” network—a fake hotspot that looks legitimate. The moment you connect, they can access your data, passwords, banking info, and private messages. Listen
Dannah Eve

Dannah Eve

82 likes

me rocking the shades yesterday at my day group ☺️
Øg Hackers Dèmøn

Øg Hackers Dèmøn

1 like

Recruiter Calls Out Scammer Who Stole A Real Persons LinkedIn Profile to Get Hired… Join me ( @cybersecuritygirl ) and Huntress on May 20th to watch more real life examples of how hackers target your social media “Send Me The Link” 👇🏼
Cybersecurity Girl

Cybersecurity Girl

2 likes

Learning on the spiritual journey!
There are few phrases more chilling in modern life than: “We can’t find your account.” Especially when the account in question contains your writing, your community, your archives, and, let’s be honest, a nontrivial chunk of your digital soul. A few weeks ago, I nearly lost my entire Substac
Cynthia L. Elliott

Cynthia L. Elliott

1 like

Amen thanks Father God Jesus Christ God morning word and prayer devil's I rebuke you your childrens Morehouse parish sheriff department officers and Mike Stone Tubbs and hackers and Elon Musk and Donald Trump and Mark Zuckerberg and Randy Tappin and Christopher Thirdkill and IT and their countr
glentrump359

glentrump359

0 likes

Kalebdavis19

Kalebdavis19

1 like

Don’t Use Airport USB Chargers!
TSA is now advising NOT to use Airport USB Chargers. Bring your own USB charging bricks. "Hackers can install malware at USB ports (we’ve been told that’s called 'juice/port jacking'). So, when you’re at an airport do not plug your phone directly into a USB port. Bring your TSA-compl
Destination & Travel Junkies

Destination & Travel Junkies

152 likes

Hackers Be Like:
#fypage
AidenIsMyself

AidenIsMyself

0 likes

Look world the 2 time removing my freedom of speech constitutional rights and laws Look world Elon Musk and Donald Trump and Mark Zuckerberg and Morehouse parish sheriff department officers and Mike Stone Tubbs KKK and hackers just pause this live 165 cause I'm exposing him following me harassi
glentrump359

glentrump359

0 likes

You shouldn’t be worried about the hackers, you should be worried about your settings. Check out ThreatLocker DAC today #ad #cybersecurity
Cybersecurity Girl

Cybersecurity Girl

25 likes

Look world this scary mutherfcker devil worshipping child Elon Musk world on my TikTok again right now removing my freedom of speech constitutional rights and laws Elon Musk and Donald Trump and Mark Zuckerberg and Morehouse parish sheriff department officers and Mike Stone Tubbs and hackers
glentrump359

glentrump359

0 likes

🚨 16 Billion passwords leaked - the largest breach ever 🚨 Here is how it happened and what you can do to be safe. #news #databreach #cybersecuritytips #onlinesafety
Cybersecurity Girl

Cybersecurity Girl

128 likes

Prayers for Jamaica 🇯🇲 — opening Hacker’s Slumber,
Cousin B

Cousin B

0 likes

King Trump
GrouchyGrandpaChannel

GrouchyGrandpaChannel

3 likes

Vibe coding is more accessible but it’s not as simple as speaking plain English😡
NO! Vibe coding is NOT as simple as people say! And if done poorly, you can get hacked 😒 45% of the apps built with AI could be vulnerable from day one. We’re talking about: 1. Hardcoded API keys 2. Missing authentication 3. Vulnerable dependencies These are common issues in AI generated c
Learn AI with Rosie Rachel

Learn AI with Rosie Rachel

0 likes

QUANTUM HACKER GNOSIS.👁️⚔️
The matrix fears awakened consciousness. Stay vigilant. Stay ready. Stay holy. Quantum hackers move with truth, gnosis, and divine precision.👁️⚔️ #QuantumHacker #ExposeTheMatrix #StayHoly #Gnosis #Fyp
theanticorporation

theanticorporation

1 like

Look world I just made this new Facebook account a minute ago Morehouse parish sheriff department officers and Mike Stone Tubbs and hackers and Elon Musk and Donald Trump and Mark Zuckerberg just locked and suspended it cause I'm sharing my legal paperwork and federal complaints I'm filling
glentrump359

glentrump359

0 likes

A woman wearing a black outfit and a large pearl necklace smiles while sitting in a room with rows of green chairs. Other individuals are visible in the background. The image features Lemon8 branding with the username @angelawrivers.
Hackers hijacked antivirus features to install mal
Hackers hijacked antivirus features to install malware - here's what we know https://www.yahoo.com/tech/cybersecurity/articles/hackers-hijacked-antivirus-features-install-140500891.html #hackers #malware #cybersecurity #antivirus
angela1957

angela1957

1 like

Amen thanks Father God Jesus Christ God evening word and prayer devil's I rebuke you your childrens Morehouse parish sheriff department officers and Mike Stone Tubbs and hackers and Elon Musk and Donald Trump and Mark Zuckerberg and Randy Tappin and Christopher Thirdkill and IT and their countr
glentrump359

glentrump359

0 likes

Replying to @Red what parts or the dark web live in your brain rent free? #scarystories #horror #eductional #darkweb
Liz Cooper🦋

Liz Cooper🦋

43 likes

See more