--- title: TeamPCP Claims Sale of Mistral AI Repositories Amid Mini Shai-Hulud Attack sha256: a1278febf59f0459055c832aeead50eb987ce9eb25c3968c0e6b35de9b95059c type: raw-article tags: [hackread,mistral-ai,security,vulnerability,repository-attack] source: newsletter source_url: https://hackread.com/teampcp-mistral-ai-repositories-mini-shai-hulud-attack/ url: https://hackread.com/teampcp-mistral-ai-repositories-mini-shai-hulud-attack/ review_value: 8 review_confidence: 8 review_recommendation: worth-reading review_stars: 4 ingested: 2026-05-16 --- # TeamPCP Claims Sale of Mistral AI Repositories Amid Mini Shai-Hulud Attack Published Time: 2026-05-14T01:37:05+01:00 Markdown Content: [![Image 2: Hackread - Cybersecurity News, Data Breaches, AI and More](https://hackread.com/wp-content/uploads/2023/08/Hackread-logo.png)](https://hackread.com/)[![Image 3: Hackread - Cybersecurity News, Data Breaches, AI and More](https://hackread.com/wp-content/uploads/2023/08/Hackread-logo.png)](https://hackread.com/) * [Hacking News](https://hackread.com/category/data-breaches/hacking-news/) * [Leaks](https://hackread.com/category/data-breaches/hacking-news/leaks-affairs/) * [WikiLeaks](https://hackread.com/category/data-breaches/hacking-news/wikileaks-affairs/) * [Anonymous](https://hackread.com/category/data-breaches/hacking-news/anonymous/) * [Technology](https://hackread.com/category/technology/) * [Android](https://hackread.com/category/technology/android/) * [Apple](https://hackread.com/category/technology/anews/) * [Google](https://hackread.com/category/technology/gnews/) * [Microsoft](https://hackread.com/category/technology/microsoft/) * [Samsung](https://hackread.com/category/technology/samsung/) * [3D](https://hackread.com/category/technology/3d/) * [How To](https://hackread.com/category/how-to/) * [Artificial Intelligence](https://hackread.com/category/artificial-intelligence/) * [Machine Learning](https://hackread.com/category/artificial-intelligence/machine-learning/) * [Cyber Crime](https://hackread.com/category/latest-cyber-crime/) * [Phishing Scam](https://hackread.com/category/latest-cyber-crime/phishing-scam/) * [Scams and Fraud](https://hackread.com/category/latest-cyber-crime/scams-and-fraud/) * [Security](https://hackread.com/category/security/) * [Malware](https://hackread.com/category/security/malware/) * [Censorship](https://hackread.com/category/cyber-events/censorship/) * [Cyber Attacks](https://hackread.com/category/cyber-events/cyber-attacks-cyber-events/) * [Crypto](https://hackread.com/category/cryptocurrency/) * [Blockchain](https://hackread.com/category/blockchain/) * [Surveillance](https://hackread.com/category/surveillance/) * [Drones](https://hackread.com/category/surveillance/drones/) * [NSA](https://hackread.com/category/surveillance/nsa/) * [Privacy](https://hackread.com/category/surveillance/privacy/) * [Gaming](https://hackread.com/category/gaming/) * [Submit Press Release](https://hackread.com/submit-press-release/) [![Image 4: Hackread - Cybersecurity News, Data Breaches, AI and More](https://hackread.com/wp-content/uploads/2023/08/Hackread-logo.png)](https://hackread.com/)[![Image 5: Hackread - Cybersecurity News, Data Breaches, AI and More](https://hackread.com/wp-content/uploads/2023/08/Hackread-logo.png)](https://hackread.com/) * [Hacking News](https://hackread.com/category/data-breaches/hacking-news/) * [Leaks](https://hackread.com/category/data-breaches/hacking-news/leaks-affairs/) * [WikiLeaks](https://hackread.com/category/data-breaches/hacking-news/wikileaks-affairs/) * [Anonymous](https://hackread.com/category/data-breaches/hacking-news/anonymous/) * [Technology](https://hackread.com/category/technology/) * [Android](https://hackread.com/category/technology/android/) * [Apple](https://hackread.com/category/technology/anews/) * [Google](https://hackread.com/category/technology/gnews/) * [Microsoft](https://hackread.com/category/technology/microsoft/) * [Samsung](https://hackread.com/category/technology/samsung/) * [3D](https://hackread.com/category/technology/3d/) * [How To](https://hackread.com/category/how-to/) * [Artificial Intelligence](https://hackread.com/category/artificial-intelligence/) * [Machine Learning](https://hackread.com/category/artificial-intelligence/machine-learning/) * [Cyber Crime](https://hackread.com/category/latest-cyber-crime/) * [Phishing Scam](https://hackread.com/category/latest-cyber-crime/phishing-scam/) * [Scams and Fraud](https://hackread.com/category/latest-cyber-crime/scams-and-fraud/) * [Security](https://hackread.com/category/security/) * [Malware](https://hackread.com/category/security/malware/) * [Censorship](https://hackread.com/category/cyber-events/censorship/) * [Cyber Attacks](https://hackread.com/category/cyber-events/cyber-attacks-cyber-events/) * [Crypto](https://hackread.com/category/cryptocurrency/) * [Blockchain](https://hackread.com/category/blockchain/) * [Surveillance](https://hackread.com/category/surveillance/) * [Drones](https://hackread.com/category/surveillance/drones/) * [NSA](https://hackread.com/category/surveillance/nsa/) * [Privacy](https://hackread.com/category/surveillance/privacy/) * [Gaming](https://hackread.com/category/gaming/) * [Submit Press Release](https://hackread.com/submit-press-release/) [![Image 6: Hackread - Cybersecurity News, Data Breaches, AI and More](https://hackread.com/wp-content/uploads/2023/08/Hackread-logo.png)](https://hackread.com/)[![Image 7: Hackread - Cybersecurity News, Data Breaches, AI and More](https://hackread.com/wp-content/uploads/2023/08/Hackread-logo.png)](https://hackread.com/) ##### The Latest ![Image 8: Hackers Use PyInstaller and AMSI Patching to Deliver XWorm RAT v7.4](https://hackread.com/wp-content/uploads/2026/05/hackers-pyinstaller-amsi-patching-xworm-rat-v7-4-110x110.jpg) [](https://hackread.com/hackers-pyinstaller-amsi-patching-xworm-rat-v7-4/) ###### [Hackers Use PyInstaller and AMSI Patching to Deliver XWorm RAT v7.4](https://hackread.com/hackers-pyinstaller-amsi-patching-xworm-rat-v7-4/) ![Image 9: CalPhishing Scam Uses EvilTokens Kit, Outlook Invites to Steal M365 Sessions](https://hackread.com/wp-content/uploads/2026/05/calphishing-eviltokens-kit-outlook-invites-m365-110x110.jpg) [](https://hackread.com/calphishing-eviltokens-kit-outlook-invites-m365/) ###### [CalPhishing Scam Uses EvilTokens Kit, Outlook Invites to Steal M365 Sessions](https://hackread.com/calphishing-eviltokens-kit-outlook-invites-m365/) ![Image 10: Fake Job Interview Apps Drop JobStealer Malware on Windows and macOS](https://hackread.com/wp-content/uploads/2026/05/fake-job-interview-jobstealer-malware-windows-macos-3-110x110.jpg) [](https://hackread.com/fake-job-interview-jobstealer-malware-windows-macos/) ###### [Fake Job Interview Apps Drop JobStealer Malware on Windows and macOS](https://hackread.com/fake-job-interview-jobstealer-malware-windows-macos/) ![Image 11: How Fintech APIs Are Modernizing Business Cash Flow Management](https://hackread.com/wp-content/uploads/2026/05/fintech-apis-modernize-business-cash-flow-management-110x110.jpg) [](https://hackread.com/fintech-apis-modernize-business-cash-flow-management/) ###### [How Fintech APIs Are Modernizing Business Cash Flow Management](https://hackread.com/fintech-apis-modernize-business-cash-flow-management/) * [Zyxel](https://hackread.com/tag/zyxel/) * [Zynga](https://hackread.com/tag/zynga/) * [Zyklon B hacker](https://hackread.com/tag/zyklon-b-hacker/) * [Zygote](https://hackread.com/tag/zygote/) * [Zurich Insurance Group](https://hackread.com/tag/zurich-insurance-group/) * [Zues Malware](https://hackread.com/tag/zues-malware/) * [Zues](https://hackread.com/tag/zues/) * [ZTNA](https://hackread.com/tag/ztna/) * [ZTA Gateways](https://hackread.com/tag/zta-gateways/) * [ZTA](https://hackread.com/tag/zta/) ![Image 12: TeamPCP Claims Sale of Mistral AI Repositories Amid Mini Shai-Hulud Attack](https://hackread.com/wp-content/uploads/2026/05/teampcp-mistral-ai-repositories-mini-shai-hulud-attack-2.png) * [Data Breaches](https://hackread.com/category/data-breaches/) * [Security](https://hackread.com/category/security/) # TeamPCP Claims Sale of Mistral AI Repositories Amid Mini Shai-Hulud Attack (Updated) TeamPCP claims to be selling alleged Mistral AI repositories on a hacker forum after the Mini Shai-Hulud attack targeted npm and PyPI ecosystems. [![Image 13](https://secure.gravatar.com/avatar/3c971597535b97dcf1c986f945aa98a632225995095afc68c2a7c0dff262d639?s=26&d=mm&r=g)by Waqas](https://hackread.com/author/hackread/ "View all posts by Waqas") May 14, 2026 3 minute read ### **_Key Points_** * **A TeamPCP-linked forum account claims to be selling internal Mistral AI repositories.** * **The post advertises roughly 5GB of files linked to AI training and inference projects.** * **As of now, no public evidence confirms the authenticity of the alleged repositories.** * **The claims surfaced days after the Mini Shai-Hulud supply chain attacks on npm and PyPI.** * **TeamPCP has been previously linked to package poisoning attacks targeting AI infrastructure.** * **The article has been updated with a statement from Mistral AI.** Only days after the **[Mini Shai-Hulud](https://hackread.com/teampcp-mini-shai-hulud-worm-npm-pypi-packages/)** supply chain attack targeted npm and PyPI packages associated with French artificial intelligence company Mistral AI, a threat actor using the TeamPCP identity is now claiming to sell what appear to be internal company repositories and source code on a hacking forum. The forum post, published a few hours ago under the **[TeamPCP](https://hackread.com/tag/TeamPCP/)** name, advertises roughly 5GB of alleged internal repositories connected to both “mistralai” and “mistral-solutions.” The actor claims the archive contains around 450 repositories covering training systems, fine-tuning projects, benchmarking tools, dashboards, inference infrastructure, experiments, and future AI projects. While the claims have not been independently verified, the listing includes dozens of repository names that appear consistent with internal engineering environments and enterprise AI development workflows. Examples shown in the post include “mistral-inference-internal,” “mistral-finetune-internal,” “chatbot-security-evaluation,” “devstral-cloud,” and “pfizer-rfp-2025.” The threat actor is asking for $25,000 in exchange for the data, claiming the repositories would otherwise be leaked publicly within a week if no buyer is found. The post also states that the seller intends to provide the archive to only one buyer. As Hackread.com **[reported](https://hackread.com/teampcp-mini-shai-hulud-worm-npm-pypi-packages/)** earlier, TeamPCP was recently linked to the Mini Shai-Hulud campaign, a large-scale software supply chain attack that poisoned hundreds of npm and PyPI packages associated with projects including Mistral AI, TanStack, OpenSearch, UiPath, and Guardrails AI. The attackers abused **[CI/CD](https://hackread.com/benefits-of-ci-cd-software-development-company/)** publishing systems and hijacked OpenID Connect tokens to distribute malicious package updates through legitimate release mechanisms. The malware was designed to steal GitHub tokens, cloud credentials, CI/CD secrets, SSH keys, and developer environment data. That earlier campaign already raised concerns about whether compromised developer credentials or publishing infrastructure could provide access beyond public package repositories. The latest forum claims now suggest the attackers may be attempting to monetize alleged internal development assets connected to AI infrastructure and enterprise tooling. The forum post itself does not include downloadable samples or technical proof confirming access to the repositories. However, it references previous TeamPCP activity **[involving](https://thehackernews.com/2026/04/pytorch-lightning-compromised-in-pypi.html)** Lightning AI and instructs buyers to verify the group’s identity through prior attack notes and forum activity. Discover more Computer Security Machine Learning & Artificial Intelligence Hacking & Cracking ### **Sample Repo Names Shared by the Threat Actor** ``` * finance.tar.gz * typhoon.tar.gz * turbine.tar.gz * xformers.tar.gz * dashboard.tar.gz * website-v3.tar.gz * devstral-cloud.tar.gz * mistral-fabric.tar.gz * kyc-doc-agent.tar.gz * mistral-surge.tar.gz * mistral-solutions.tar.gz * finetuning-feedback.tar.gz * surge-validators.tar.gz * pfizer-rfp-2025.tar.gz * mistral-common-internal.tar.gz * mistral-compute-poc.tar.gz * piper-segmentation.tar.gz * mistral_finance_agent.tar.gz * mistral-lawyer-internal.tar.gz * mistral-finetune-internal.tar.gz * chatbot-security-evaluation.tar.gz * mistral-inference-private.tar.gz * cma-customer-care-internal.tar.gz * mistral-inference-internal.tar.gz ``` At the time of writing, Mistral AI has not publicly commented on the claims. There is also no public evidence confirming that the files, if authentic, originated from the company’s internal systems. [![Image 14: TeamPCP Claims Sale of Mistral AI Repositories Amid Mini Shai-Hulud Attack](https://hackread.com/wp-content/uploads/2026/05/teampcp-mistral-ai-repositories-mini-shai-hulud-attack-1-814x1024.png)](https://hackread.com/wp-content/uploads/2026/05/teampcp-mistral-ai-repositories-mini-shai-hulud-attack-1.png) TeamPCP-linked account offering the alleged Mistral AI repositories (Image credit: Hackread.com) Even so, the situation suggests that attacks targeting AI software environments are moving beyond poisoned packages and stolen credentials, with threat actors now appearing to focus on internal development systems, enterprise tooling, and AI infrastructure. As AI companies continue building cloud-hosted training, inference, and autonomous agent systems, developer credentials and **[CI/CD environments](https://hackread.com/aembit-extends-secretless-ci-cd-with-credential-lifecycle-management-for-gitlab/)** are becoming increasingly valuable targets for groups seeking access to intellectual property and enterprise infrastructure. Hackread.com has reached out to Mistral AI for comment and will update this story if a response is received. ### Update – Statement from Mistral AI In a statement shared with Hackread.com, a Mistral AI spokesperson confirmed that attackers temporarily compromised one of the company’s codebase management systems on May 12, 2026, through a third-party software supply chain attack. Discover more Software Technology News Antivirus & Malware According to the company, the attackers contaminated some SDK packages for a limited time before the incident was contained. Mistral AI said it quickly neutralized the attack, secured its infrastructure, and launched a forensic [investigation](https://docs.mistral.ai/resources/security-advisories) with relevant authorities. The company added that the attackers only accessed certain non-core code repositories, while hosted services, managed user data, and research and testing environments were not affected. ##### [Waqas](https://hackread.com/author/hackread/) [![Image 15](https://secure.gravatar.com/avatar/3c971597535b97dcf1c986f945aa98a632225995095afc68c2a7c0dff262d639?s=80&d=mm&r=g)](https://hackread.com/author/hackread/) I am a UK-based cybersecurity journalist with a passion for covering the latest happenings in cybersecurity and tech world. I am also into gaming, reading and investigative journalism. [View Posts](https://hackread.com/author/hackread/) * [AI](https://hackread.com/tag/ai/) * [Cyber Attack](https://hackread.com/tag/cyber-attack/) * [Cyber Crime](https://hackread.com/tag/cyber-crime/) * [Cybersecurity](https://hackread.com/tag/cybersecurity/) * [Mistral AI](https://hackread.com/tag/mistral-ai/) * [NPM](https://hackread.com/tag/npm/) * [PyPI](https://hackread.com/tag/pypi/) * [Supply Chain](https://hackread.com/tag/supply-chain/) * [TeamPCP](https://hackread.com/tag/teampcp/) ##### Leave a Reply [Cancel reply](https://hackread.com/teampcp-mistral-ai-repositories-mini-shai-hulud-attack/#respond) Your email address will not be published.Required fields are marked * Comment * Name * Email * Website Δ View Comments (0) ##### Subscription Form ![Image 16: loader](https://hackread.com/wp-includes/images/spinner.gif) Email Address* FIRSTNAME LASTNAME ##### Latest Posts * [Hackers Use PyInstaller and AMSI Patching to Deliver XWorm RAT v7.4](https://hackread.com/hackers-pyinstaller-amsi-patching-xworm-rat-v7-4/) * [CalPhishing Scam Uses EvilTokens Kit, Outlook Invites to Steal M365 Sessions](https://hackread.com/calphishing-eviltokens-kit-outlook-invites-m365/) * [Fake Job Interview Apps Drop JobStealer Malware on Windows and macOS](https://hackread.com/fake-job-interview-jobstealer-malware-windows-macos/) * [How Fintech APIs Are Modernizing Business Cash Flow Management](https://hackread.com/fintech-apis-modernize-business-cash-flow-management/) * [FamousSparrow Targeted Oil and Gas Industry via MS Exchange Server Exploit](https://hackread.com/famoussparrow-oil-gas-ms-exchange-server-exploit/) ##### PRESS RELEASE * ![Image 17](https://hackread.com/wp-content/uploads/2026/05/Lyrie_and_Anthropic_1778138816A1kmRs3pAH-80x80.jpg) [](https://hackread.com/lyrie-ai-joins-first-batch-of-anthropics-cyber-verification-program/) * [Press Release](https://hackread.com/category/press-release/) ### [Lyrie.ai Joins First Batch of Anthropic’s Cyber Verification Program](https://hackread.com/lyrie-ai-joins-first-batch-of-anthropics-cyber-verification-program/) [by CyberNewswire](https://hackread.com/author/cybernewswire/ "View all posts by CyberNewswire") * ![Image 18](https://hackread.com/wp-content/uploads/2026/05/LuxSci_Secure_Email_Mid-Sized_PR_1777922928HSMMEp3uoy-80x80.jpg) [](https://hackread.com/luxsci-launches-enterprise-grade-hipaa-compliant-email-security-for-mid-sized-healthcare-organizations/) * [Press Release](https://hackread.com/category/press-release/) ### [LuxSci Launches Enterprise-Grade HIPAA-Compliant Email Security for Mid-Sized Healthcare Organizations](https://hackread.com/luxsci-launches-enterprise-grade-hipaa-compliant-email-security-for-mid-sized-healthcare-organizations/) [by CyberNewswire](https://hackread.com/author/cybernewswire/ "View all posts by CyberNewswire") * ![Image 19](https://hackread.com/wp-content/uploads/2026/05/1200_700_1776732787DlSbx2MTHb-80x80.jpg) [](https://hackread.com/criminal-ip-and-securonix-threatq-collaborate-to-enhance-threat-intelligence-operations/) * [Press Release](https://hackread.com/category/press-release/) ### [Criminal IP and Securonix ThreatQ Collaborate to Enhance Threat Intelligence Operations](https://hackread.com/criminal-ip-and-securonix-threatq-collaborate-to-enhance-threat-intelligence-operations/) [by CyberNewswire](https://hackread.com/author/cybernewswire/ "View all posts by CyberNewswire") * ![Image 20](https://hackread.com/wp-content/uploads/2026/04/Picture1_1777442433Pk2kOwYHqu-80x80.jpg) [](https://hackread.com/brinker-introduces-a-novel-approach-to-deepfake-detection/) * [Press Release](https://hackread.com/category/press-release/) ### [Brinker Introduces a Novel Approach to Deepfake Detection](https://hackread.com/brinker-introduces-a-novel-approach-to-deepfake-detection/) [by CyberNewswire](https://hackread.com/author/cybernewswire/ "View all posts by CyberNewswire") * ![Image 21](https://hackread.com/wp-content/uploads/2026/04/BreachLock_Named_Representative_Vendor_in_2026_Gar_1776721618nJIDraNFL9-80x80.jpg) [](https://hackread.com/breachlock-named-representative-vendor-in-the-2026-gartner-market-guide-for-adversarial-exposure-validation/) * [Press Release](https://hackread.com/category/press-release/) ### [BreachLock Named Representative Vendor in the 2026 Gartner Market Guide for Adversarial Exposure Validation](https://hackread.com/breachlock-named-representative-vendor-in-the-2026-gartner-market-guide-for-adversarial-exposure-validation/) [by CyberNewswire](https://hackread.com/author/cybernewswire/ "View all posts by CyberNewswire") ##### Related Posts ![Image 22: New Wave of Cyberattacks Targeting MS Exchange Servers](https://hackread.com/wp-content/uploads/2023/01/ProxyNotShell-OWASSRF-targets-microsoft-exchange-servers-260x195.jpg) Read More [](https://hackread.com/ms-exchange-servers-cyberattacks/) * [Malware](https://hackread.com/category/security/malware/) * [Security](https://hackread.com/category/security/) ## [New Wave of Cyberattacks Targeting MS Exchange Servers](https://hackread.com/ms-exchange-servers-cyberattacks/) Cybercriminals are leveraging two exploit chains (ProxyNotShell/OWASSRF) to target Microsoft Exchange servers, as warned by Bitdefender Labs. [by Waqas](https://hackread.com/author/hackread/ "View all posts by Waqas") * [Security](https://hackread.com/category/security/) * [Google News](https://hackread.com/category/technology/gnews/) * [Scams and Fraud](https://hackread.com/category/latest-cyber-crime/scams-and-fraud/) ## [Gmail’s Spam Filter Not Impenetrable For Hackers](https://hackread.com/gmails-spam-filter-not-impenetrable-for-hackers/) Most of us today use Gmail as our primary email platform. It is indeed a very useful platform… [by Waqas](https://hackread.com/author/hackread/ "View all posts by Waqas") * [Malware](https://hackread.com/category/security/malware/) * [Security](https://hackread.com/category/security/) ## [CopperStealer malware stealing Facebook, Apple, Google passwords](https://hackread.com/copperstealer-malware-steal-facebook-apple-google-passwords/) The credential-stealing malware was found in keygen and Cracks' website to circumvent licensing restrictions to legit software. [by Waqas](https://hackread.com/author/hackread/ "View all posts by Waqas") ![Image 23: Bouygues Telecom Hit by Cyberattack, 6.4 Million Customers Affected](https://hackread.com/wp-content/uploads/2025/08/bouygues-telecom-hit-by-cyberattack-6-4-million-customers-affected-2-260x195.jpg) Read More [](https://hackread.com/bouygues-telecom-cyberattack-6-4m-customers-affected/) * [Security](https://hackread.com/category/security/) * [Cyber Attacks](https://hackread.com/category/cyber-events/cyber-attacks-cyber-events/) ## [Bouygues Telecom Hit by Cyberattack, 6.4 Million Customers Affected](https://hackread.com/bouygues-telecom-cyberattack-6-4m-customers-affected/) A cyberattack on Bouygues Telecom exposed data for 6.4 million customers. Find out what information was compromised and… [by Deeba Ahmed](https://hackread.com/author/deeba/ "View all posts by Deeba Ahmed") [![Image 24: Hackread - Cybersecurity News, Data Breaches, AI and More](https://hackread.com/wp-content/uploads/2023/08/Hackread-logo-footer.png)](https://hackread.com/)[![Image 25: Hackread - Cybersecurity News, Data Breaches, AI and More](https://hackread.com/wp-content/uploads/2023/08/Hackread-logo-footer.png)](https://hackread.com/) HACKREAD is a news platform that centers on Cybersecurity, AI, InfoSec, Cyber Crime and Hacking News with full-scale reviews on Crypto and Technology trends. Founded in 2011, HackRead is based in the United Kingdom. Copyright © 2026 HackRead The display of third-party trademarks and trade names on the site do not necessarily indicate any affiliation or endorsement of Hackread.com. If you click an affiliate link and buy a product or service, we may be paid a fee by that merchant. * [About Us](https://hackread.com/about-us/) * [Our Team](https://hackread.com/team/) * [Contact Us](https://hackread.com/contact-us/) * [Our Mission](https://hackread.com/our-mission/) * [Privacy Policy](https://hackread.com/privacy-policy/) [](https://hackread.com/teampcp-mistral-ai-repositories-mini-shai-hulud-attack/#top)