TeamPCP Claims Sale of Mistral AI Repositories Amid Mini Shai-Hulud Attack
2026-05-14T08:51:42Z•96f00fe5bf2a77255fabd7fa89971a4b3ac2734862db248758bd042a6724b648
Canvas-LMSGitHub-hosted-payloadsMini-Shai-HuludMistral-AIOIDC-token-hijackOperation-HumanitarianBaitPwn2OwnPyPIPython-spywareShinyHuntersTanStackTeamPCPUiPathbrowser-passwordscookiescredential-stealerdark-webdark-web-marketplacedata-exfiltrationdomain-suspensionfake-installernpmpackage-poisoningsupply-chainzero-day-disclosures
What happened
HackRead feed reports multiple active supply-chain and data-theft incidents: TeamPCP claims to be selling alleged Mistral AI repositories after using the self‑propagating “Mini Shai‑Hulud” worm to poison 400+ npm and PyPI packages (via OIDC token hijacking), impacting projects including TanStack, Mistral AI and UiPath. ShinyHunters reached an agreement with Instructure to return/destroy stolen Canvas LMS data and said its public domain was suspended, moving operations to onion services. Researchers disclosed a fake Claude Code installer campaign that steals browser passwords and cookies, and P
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- 96f00fe5bf2a77255fabd7fa89971a4b3ac2734862db248758bd042a6724b648
- Enrichment time
- 2026-05-14T08:51:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.