Junglewise Threat Intelligence

Mistral AI npm packages supply chain compromise with broken dropper

Severity: low · CVSS 0 · Published 2026-05-18

Executive brief

Several Mistral AI software libraries were briefly compromised in a supply chain attack where malicious code was injected into official releases. The libraries are used by developers to integrate Mistral's AI services into applications. While the malicious code was intended to download and run further malware, the "dropper" component was broken and failed to execute, resulting in no practical impact on users or data.

Technical details

A supply chain attack, linked to the TanStack security incident and an affected developer device, led to the publication of compromised versions of @mistralai/mistralai, @mistralai/mistralai-azure, and @mistralai/mistralai-gcp. The packages contained a malicious dropper (CWE-506) designed to execute a payload. However, the dropper was non-functional because setup.mjs attempted to execute 'tanstack_runner.js' while the actual payload file was named 'router_init.js', causing an ENOENT error. Although the Bun runtime was downloaded to a temporary directory, no malicious payload execution occurred. The compromised versions were available on npm between May 11 and May 12, 2026, and have since been removed.

Affected products

  • Mistral AI @mistralai/mistralai 2.2.2, 2.2.3, 2.2.4
  • Mistral AI @mistralai/mistralai-azure 1.7.1, 1.7.2, 1.7.3
  • Mistral AI @mistralai/mistralai-gcp 1.7.1, 1.7.2, 1.7.3

Timeline

  • 2026-05-11: exploited: Compromised versions first available on npm.
  • 2026-05-12: patched: Compromised versions removed from npm.
  • 2026-05-18: advisory: GitHub advisory published.

References

Related threats