Junglewise Threat Intelligence

Mistral AI npm packages supply chain attack (broken dropper)

Severity: low · CVSS 3.1 · Published 2026-05-18

Executive brief

Three Mistral AI npm packages were compromised in a supply chain attack related to the TanStack security incident, with malicious code attempting to download and execute a payload. The attack was unsuccessful due to broken implementation—the dropper script references an incorrect filename and executes before cleanup, meaning no actual payload runs. Nevertheless, affected versions were available briefly and may exist in lockfiles, build caches, or container images, requiring removal and system cleanup as a precaution.

Technical details

The vulnerability is a supply chain attack in which three Mistral AI npm packages were compromised via a malicious developer device (not Mistral infrastructure). Affected versions contained a dropper payload designed to download and execute arbitrary code. However, the implementation was broken: setup.mjs references a file named tanstack_runner.js but the actual payload is named router_init.js, causing execFileSync to fail with ENOENT; additionally, the temporary directory is wiped before the payload could execute. The dropper had no successful impact, though affected versions (available May 11 22:45 UTC to May 12 01:53 UTC) may persist in dependency lockfiles, build artifacts, and container images, warranting complete removal and system remediation.

Affected products

  • Mistral AI mistralai 2.2.2, 2.2.3, 2.2.4
  • Mistral AI mistralai-azure 1.7.1, 1.7.2, 1.7.3
  • Mistral AI mistralai-gcp 1.7.1, 1.7.2, 1.7.3

Timeline

  • 2026-05-11: other: Compromised versions published to npm
  • 2026-05-12: other: Compromised versions removed from npm; exposure window closed
  • 2026-05-18: disclosed: Advisory published

References

Related threats