Mark RadarMARK RADAR
EN

AI Supply Chain Hit by Major Security Breaches Involving Mistral Package and Fake OpenAI Model

2 reports · First detected 2026-05-13 · Last active 2026-05-14

AI development relies heavily on PyPI packages and Hugging Face model repositories, with developers often installing and running third-party code directly. If official release processes or popularity rankings are manipulated, malware can exploit trusted brands to enter development environments and steal cloud credentials, access tokens, SSH keys and cryptocurrency wallet seed phrases. The risk can then spread through CI/CD systems. No financial losses were disclosed in either case.

On May 7, 2026, HiddenLayer discovered a fake model impersonating OpenAI on Hugging Face. It rose to No. 1 on the trending chart within 18 hours, amassing 244,000 downloads and 667 likes. On May 12, Microsoft disclosed that version 2.4.6 of Mistral AI’s PyPI package had been injected with information-stealing code. The malicious version was uploaded at 00:05 UTC and removed at 03:05 UTC.

All Coverage

2 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)