Skip to content

Supply chain compromise in mistralai Python package

github.com/mistralai
6 pointsmeander_water3 comments
On HN

Comments

I use mistralai and their API is quite good. Luckily I like to pin the versions and upgrade manually a little bit later just in case of this kind of unfortunate events.

Have version lock as well, but dependency resolution seems to be messed up for a time. Started unrelated upgrade action and got blocked :)

This appears to be part of the same Mini Shai-Hulud campaign affecting Tanstack Router https://www.securityweek.com/tanstack-mistral-ai-uipath-hit-...

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.