TeamPCP offers Mistral AI code repositories for sale

TeamPCP says it is selling nearly 450 repositories tied to Mistral AI for $25,000, and claims it will leak the data if no buyer appears within a week. Mistral AI said the incident came after a supply-chain attack hit a developer device, but said its hosted services and core repositories were not compromised.

TeamPCP offers Mistral AI code repositories for sale

The TeamPCP hacker group is threatening to leak source code tied to Mistral AI unless it finds a buyer for the data. In a post on a hacker forum, the group said it wants $25,000 for nearly 450 repositories and claimed the data includes almost 5 gigabytes of internal code.

Mistral AI confirmed to BleepingComputer that a codebase management system was compromised after the Mini Shai-Hulud software supply-chain attack. The company said the incident began when official packages from TanStack and Mistral AI were compromised through stolen CI/CD credentials and legitimate workflows, then spread to hundreds of other software projects on npm and PyPI.

⚡ New to this?

This matters because source code theft can expose how a company builds, tests, and ships software, and that can help attackers or competitors. A software supply-chain attack is when criminals compromise a trusted tool, package, or developer workflow and use that path to reach other systems. SDK means software development kit, the code components developers use to build apps that talk to a platform.

🦞 OpenClaw angle

If you run self-hosted agents or CI/CD pipelines, treat package installs and developer credentials as high-value targets. Pin dependencies, verify package integrity, and isolate build environments so a compromised library cannot reach internal repos or signing keys. Also rotate any tokens used by automation jobs and review whether your agents can access source code, secrets, or release-signing systems they do not strictly need.

Those affected projects included UiPath, Guardrails AI, and OpenSearch, according to the report. Mistral said TeamPCP managed to contaminate some of its software development kit, or SDK, packages for a brief period. SDK packages are the code libraries developers use to connect applications to a service or platform.

According to TeamPCP, the stolen material includes internal repositories and source code used for training, fine-tuning, benchmarking, model delivery, and inference in experiments and future projects. The group said it would either sell the data for $25,000 “buy it now,” accept the best offer, or leak the files for free if no buyer appears within a week.

The hackers also said the price is negotiable and invited interested buyers to make their own offers. Their forum post suggests the data is being marketed as a limited sale to one buyer, with a promise to delete the files if the ransom-like demand is met.

Mistral, however, said its forensic investigation found that the impacted data was not part of its core code repositories. In a statement to BleepingComputer, the company said neither its hosted services, managed user data, nor its research and testing environments were compromised.

The company also said the breach followed the compromise of a developer device in the TanStack supply-chain attack. That attack has now been tied to several companies beyond Mistral.

Earlier today, OpenAI confirmed that the TanStack incident affected systems used by two employees who had access to a limited set of internal source code repositories. OpenAI said a small set of credentials was stolen from the repositories, but investigators found no evidence that they were used in additional attacks.

OpenAI also said it rotated the code-signing certificates exposed in the incident and warned macOS users to update their OpenAI desktop apps before June 12, or the software may fail to launch and stop receiving updates.

Source: BleepingComputer ↗

More from Security News