-
A hacker using the alias mrwho claims to have the full source code of Mistral AI and is advertising it for sale, but the claim remains unverified.
-
The ad contains 339 files and a sample called webstral, which appears to be a prototype AI browser agent using the API of Mistral.
-
Some archives available within the new list match names from a supply chain breach that occurred in May this year, leaving the situation obscure about whether the data is new or merely a re-packaged old data.
A hacker recently posted a new claim about Mistral AI on a cybercrime forum. The user, known as mrwho, advertised the sale of what they call the company’s entire source code. The listing went up on September 16 this year. The seller also claims the French AI firm was breached again after a prior incident in May.
According to the directory structure from the hacker, there are a total of 339 files and archives in the list pertaining to multiple internal projects. Some of the names imply private/internal code, including mistral-inference-private, mistral-inference-internal, and mistral-finetune-internal. The list also includes infrastructure tools like sre-infra, sre-kubernetes-tools, network, and model-delivery.
The Details of the Leaked Sample Revealed
The hacker published several samples to back up the claim. There is a review of one of them, named webstral. The project looks like a prototype AI assistant built directly into the Chrome browser. Its code lets a user ask the AI to perform actions on the web.
The functions in the code allow the agent to navigate to an address, read page content, and interact with elements. The agent can analyze a page, click buttons, and fill in forms. The sample uses the Mistral API and references the model devstral-medium-2507.
The extension relies on the API key issued to the user, which resides locally in the browser. It was also discovered that no existing Mistral API keys are hardcoded directly in the code questioned.
The importance of this sample resides in the fact that it doesn’t appear to be a common public library. The code holds comprehensive agent logic that is applicable for browser use, accounting for page analysis, recommendation of actions, conversation history, and user interactions with site objects.
All these features confirm that the archive might contain prototypes or development tools related to the work of Mistral.
Links to the May Incident and Prior Claims
The timing of this claim raises questions. Mistral AI confirmed a separate security incident back in May 2026. On the 12th of May, a hacker breached a code management system of the organization by performing a software supply chain attack on a third-party app.
According to statements from the organization, the hacker managed to corrupt a set of SDK packages in a limited time. But the intruder did not gain access to the hosted services, user information, or research facilities.
A group called TeamPCP claimed responsibility for that May breach. They said they stole about 5 GB of internal repositories and source code covering training, fine-tuning, and model delivery. They offered the data for $25,000 and threatened to leak it for free if no buyer appeared.
Several archives in the new September list appeared in the earlier May claim as well. This overlap suggests two possibilities. The new seller may have repackaged data from the May incident.
Alternatively, a fresh breach may have occurred. The seller claims the source is unrenewed development secrets from the earlier attack. No technical proof published with the new claim establishes a September intrusion. The presence of commits or files dated after May would strongly support the claim of new access.
The Bigger Picture for AI Supply Chains
The May incident highlighted a growing risk for AI companies. Attackers did not breach the servers of Mistral directly. Instead, the hackers attacked TanStack, which is considered to be a popular open-source library. The hackers then published infected package versions by using the stolen credentials for CI/CD and subsequently spread the malware to over 170 packages on npm and PyPI.
Besides the initially mentioned projects, the attack also affected other important projects. The compromised packages include some from UiPath, Guardrails AI, and OpenSearch. The malware, named Mini Shai-Hulud, acts as a worm by stealing victims’ usernames and passwords from one package to infect others.
The wider malware ecosystem also includes ransomware samples that threat actors share or advertise on underground forums. In a separate case, a dark web post offered an alleged Windows 10 ransomware sample for free, highlighting how malicious code can circulate publicly before researchers or security teams can fully assess it.
Mistral AI had stated earlier that the attack did not happen due to the interception of their main infrastructure. They explained that this attack originated from an already compromised device of a developer at the company. The company asserted that they managed to handle the situation quickly and did not find any traces of the compromise of important repositories.
The new incident can mean that Mistral will have to investigate once again. If the contents in the September files turn out to be real, they can compromise private internal software and prototypes. Due to the overlap in claims, it is possible that some data may have already leaked into the public domain.