AI Supply Chain Hit by Major Security Breaches Involving Mistral Package and Fake OpenAI Model
AI development relies heavily on PyPI packages and Hugging Face model repositories, with developers often installing and running third-party code directly. If official release processes or popularity rankings are manipulated, malware can exploit trusted brands to enter development environments and steal cloud credentials, access tokens, SSH keys and cryptocurrency wallet seed phrases. The risk can then spread through CI/CD systems. No financial losses were disclosed in either case.
On May 7, 2026, HiddenLayer discovered a fake model impersonating OpenAI on Hugging Face. It rose to No. 1 on the trending chart within 18 hours, amassing 244,000 downloads and 667 likes. On May 12, Microsoft disclosed that version 2.4.6 of Mistral AI’s PyPI package had been injected with information-stealing code. The malicious version was uploaded at 00:05 UTC and removed at 03:05 UTC.
All Coverage
2 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.