Executive Summary
In May 2026, the TeamPCP hacker group infiltrated Mistral AI's codebase management system, exfiltrating nearly 5 gigabytes of internal repositories and source code. This breach was part of the broader 'Mini Shai-Hulud' supply-chain attack, which compromised official packages from TanStack and Mistral AI through stolen CI/CD credentials and legitimate workflows. The attackers are now demanding $25,000 for the stolen data, threatening to leak it publicly if a buyer isn't found within a week.
This incident underscores the escalating threat of supply-chain attacks targeting software development processes. Organizations must prioritize securing their CI/CD pipelines and implement robust monitoring to detect unauthorized access promptly.
Why This Matters Now
The TeamPCP breach highlights the urgent need for organizations to fortify their software supply chains against increasingly sophisticated attacks that exploit trusted development tools and processes.
Attack Path Analysis
The attack began with the compromise of Mistral AI's codebase management system through stolen CI/CD credentials, leading to the contamination of SDK packages. The attackers then escalated privileges by exploiting these credentials to access and manipulate internal repositories. Subsequently, they moved laterally within the network to access additional sensitive data and systems. Establishing command and control, the attackers maintained persistent access to Mistral AI's infrastructure. They exfiltrated nearly 5 gigabytes of internal repositories and source code. Finally, they impacted the organization by threatening to leak the stolen data unless a buyer was found.
Kill Chain Progression
Initial Compromise
Description
Attackers compromised Mistral AI's codebase management system by stealing CI/CD credentials, leading to the contamination of SDK packages.
Related CVEs
CVE-2026-45321
CVSS 9.6A critical supply chain attack on TanStack NPM packages allowed attackers to publish malicious versions under trusted identities, leading to potential credential theft and unauthorized code execution.
Affected Products:
TanStack TanStack Router – *
Mistral AI Mistral AI SDK – 2.2.2, 2.2.3, 2.2.4
Mistral AI Mistral AI Azure SDK – 1.7.1, 1.7.2, 1.7.3
Mistral AI Mistral AI GCP SDK – 1.7.1, 1.7.2, 1.7.3
Mistral AI Mistral AI PyPI Package – 2.4.6
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Valid Accounts
Unsecured Credentials: Credentials in Files
Supply Chain Compromise: Compromise Software Dependencies and Development Tools
Application Layer Protocol: Web Protocols
Exfiltration Over Web Service: Exfiltration to Cloud Storage
Inhibit System Recovery
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure the integrity of software and firmware
Control ID: 6.3.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Direct supply chain attack targeting AI companies like Mistral compromised SDK packages, exposing development repositories and threatening software integrity across development workflows.
Information Technology/IT
TeamPCP's supply chain compromise via stolen CI/CD credentials demonstrates critical vulnerabilities in IT infrastructure, requiring enhanced egress security and zero trust segmentation.
Computer/Network Security
Security firms face reputational risk from supply chain attacks affecting tools like TanStack, necessitating improved threat detection capabilities and multicloud visibility controls.
Financial Services
AI model source code theft creates compliance risks under PCI DSS requirements, demanding stronger encrypted traffic controls and egress policy enforcement mechanisms.
Sources
- TeamPCP hackers advertise Mistral AI code repos for salehttps://www.bleepingcomputer.com/news/security/teampcp-hackers-advertise-mistral-ai-code-repos-for-sale/Verified
- Security advisories | Mistral Docshttps://docs.mistral.ai/resources/security-advisoriesVerified
- CVE-2026-45321: Critical Supply Chain Attack on TanStack NPM Packageshttps://www.thehackerwire.com/cve-2026-45321-critical-supply-chain-attack-on-tanstack-npm-packages/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have limited the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to exploit stolen credentials to access the codebase management system would likely be constrained, reducing the risk of initial compromise.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges and access internal repositories would likely be constrained, reducing the scope of unauthorized access.
Control: East-West Traffic Security
Mitigation: The attacker's ability to move laterally within the network would likely be constrained, reducing the risk of accessing additional sensitive data and systems.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish and maintain command and control channels would likely be constrained, reducing the risk of persistent access.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate large volumes of data would likely be constrained, reducing the risk of data loss.
The attacker's ability to leverage stolen data for extortion would likely be constrained, reducing the potential impact on operations and reputation.
Impact at a Glance
Affected Business Functions
- Software Development
- Research and Development
- Customer Support
Estimated downtime: 3 days
Estimated loss: $25,000
Approximately 450 internal repositories containing source code for training, fine-tuning, benchmarking, model delivery, and inference.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to enforce least privilege access and prevent unauthorized lateral movement.
- • Enhance Egress Security & Policy Enforcement to monitor and control outbound traffic, mitigating data exfiltration risks.
- • Deploy Inline IPS (Suricata) to detect and prevent exploitation attempts and malicious payloads.
- • Utilize Multicloud Visibility & Control to gain comprehensive insights into network traffic and detect anomalous activities.
- • Strengthen Threat Detection & Anomaly Response capabilities to identify and respond to suspicious behaviors promptly.



