The hackers secretly inserted malware into the Mistral AI installation package.
The hackers secretly inserted malware into the Mistral AI installation package and tricked the victim into downloading it.
According to a report by the website, Emerge has mentioned the detection of a campaign in which hackers insert malware on an AI tool popular with developers like Mistral AI. This tool is available for download on the PyPI platform, a source of software to work with the Python language used by developers. According to a review by the Microsoft Threat Intelligence research team from Microsoft, the malware code hidden in the AI tool package is automatically run when it is detected on the Linux operating system, where the script downloads the second payload file called transformers.pyz. The research team identified it as a naming similar to the library of Hugging Face Transformers to perform the environment of software development and machine learning.
The research team determined that the malware was a malware type that stole data from the victim or an Infostealer that was primarily responsible for password theft and Token access to the developer's system. It also found that the malware was avoided on Russian-language machines, and in some cases if it was detected that the malware was running within the area of Israel or Iran, the malware would randomly delete files on the system. Therefore, the research team recommended that malware be separated from the company's network immediately, including address blocks associated with the malware, as well as changing the code. All passes. To secure internal information and limit potential damage.
In that attack, Mistral acknowledged that it was a supply chain attack, a result of which TanStack was attacked on a supply chain attack called "Shai-Hulud," which led to malware scripts being fielded on packages distributed through NPM and PyPI. At this time, the development team was dealing with the affected developers, while confirming that the infrastructure associated with Mistral AI was not compromised.
# Trending # Lemon 8 Howtoo # lemon 8 diary # mistral # freedomhack

































































































