security
May 15, 2026
By Teun
TeamPCP offers Mistral AI code repositories for sale
TeamPCP says it is selling nearly 450 repositories tied to Mistral AI for $25,000, and claims it will leak the data if no buyer appears within a week. Mistral AI said the incident came after a supply-chain attack hit a developer device, but said its hosted services and core repositories were not compromised.
The TeamPCP hacker group is threatening to leak source code tied to Mistral AI unless it finds a buyer for the data. In a post on a hacker forum, the group said it wants $25,000 for nearly 450 repositories and claimed the data includes almost 5 gigabytes of internal code.
Mistral AI confirmed to BleepingComputer that a codebase management system was compromised after the Mini Shai-Hulud software supply-chain attack. The company said the incident began when official packages from TanStack and Mistral AI were compromised through stolen CI/CD credentials and legitimate workflows, then spread to hundreds of other software projects on npm and PyPI.
Those affected projects included UiPath, Guardrails AI, and OpenSearch, according to the report. Mistral said TeamPCP managed to contaminate some of its software development kit, or SDK, packages for a brief period. SDK packages are the code libraries developers use to connect applications to a service or platform.
According to TeamPCP, the stolen material includes internal repositories and source code used for training, fine-tuning, benchmarking, model delivery, and inference in experiments and future projects. The group said it would either sell the data for $25,000 “buy it now,” accept the best offer, or leak the files for free if no buyer appears within a week.
The hackers also said the price is negotiable and invited interested buyers to make their own offers. Their forum post suggests the data is being marketed as a limited sale to one buyer, with a promise to delete the files if the ransom-like demand is met.
Mistral, however, said its forensic investigation found that the impacted data was not part of its core code repositories. In a statement to BleepingComputer, the company said neither its hosted services, managed user data, nor its research and testing environments were compromised.
The company also said the breach followed the compromise of a developer device in the TanStack supply-chain attack. That attack has now been tied to several companies beyond Mistral.
Earlier today, OpenAI confirmed that the TanStack incident affected systems used by two employees who had access to a limited set of internal source code repositories. OpenAI said a small set of credentials was stolen from the repositories, but investigators found no evidence that they were used in additional attacks.
OpenAI also said it rotated the code-signing certificates exposed in the incident and warned macOS users to update their OpenAI desktop apps before June 12, or the software may fail to launch and stop receiving updates.