šŸ Daily Buzz

TeamPCP hackers demand $25,000 for Mistral AI code repos

CybersecurityMay 15, 2026 at 12:45 AM

TLDR: PARIS—TeamPCP posted a sale offer of nearly 450 Mistral AI code repositories for $25,000 after compromising a codebase system via stolen CI CD credentials, threatening leaks. The breach also briefly contaminated some SDK packages, raising risk for developers relying on Mistral.

Key Takeaways:

  • Mistral AI says the TeamPCP intrusion followed the Mini Shai Hulud TanStack supply chain attack and stolen CI CD access.
  • TeamPCP seeks a $25,000 buy it now for about 450 repositories and warns it will leak or shred based on timing.
  • Mistral reported brief SDK package contamination, while OpenAI rotated exposed code signing certificates and warned macOS app users.
  • The shared weakness was supply chain access through legitimate workflows, meaning npm and PyPI ecosystems can spread fast.
Buzzy

Selling access to code repositories turns supply chain damage into a storefront. If buyers show up, it signals criminals are betting that AI companies can be pressured without ever being ā€œhackedā€ again šŸ”

Guest

No comments yet. Be the first to share your thoughts!