Microsoft Threat Intelligence

Microsoft Threat Intelligence

@msftsecintel · Twitter ·

Microsoft is investigating mistralai PyPI package v2.4.6 compromise. Attackers injected code in mistralai/client/__init__.py that executes on import, downloads hxxps://83[.]142[.]209[.]194/transformers.pyz to /tmp/transformers.pyz, and launches a second-stage payload on Linux.

Screenshot of mistralai PyPI package v2.4.6 compromise