Mistral denies a fresh security breach, but the code on sale looks a lot like May's leak

Mistral denies it was hacked again

by · TechRadar

News By Rahim Amir Published 22 September 2026

(Image credit: Mistral)

Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter


  • Seller claims to be offering Mistral AI's full source code and says the company was breached again after May 2026 attack
  • Mistral says an investigation found no evidence of new unauthorized access but has not stated whether the listed code is genuine
  • No customer data has surfaced in analyzed samples, and nobody has shown files created after the May incident

A seller on a cybercrime forum says French giant Mistral AI has been hacked again and is offering what they call the company's full source code for sale.

The September 16 2026 post by an account using the handle "mrwho" consists of a listing titled "Selling mistral.ai Source Code" on an English-language cybercrime forum, according to The CyberSec Guru, pricing the material in Monero only before it attempted to steer potential buyers to Session or Telegram.

Mistral AI's own team has refuted this, stating it has "found no evidence to support this claim."

Latest Videos FromTechRadarWatch full video here:

Not Mistral's first hacking-centric PR problem

Mistral's earlier hacking incident is undisputed - in May 2026, the Mini Shai-Hulud supply chain campaign, attributed to the TeamPCP group, spread from compromised TanStack packages to hundreds of npm and PyPI projects.

Mistral's own security advisory MAI-2026-002 says an automated worm led to compromised versions of its SDKs being published for a few hours on May 11 and 12, and that an affected developer device was involved. Microsoft Threat Intelligence found that a poisoned Mistral AI Python package fetched a second-stage credential stealer that allowed the attack to exploit users.

Mistral went further in statements to reporters than in its advisory. It told BleepingComputer that attackers had compromised a codebase management system and "contaminated some of our SDK packages for a brief period," while insisting that hosted services, managed user data, and research and testing environments were untouched. It also told HackRead that only certain non-core repositories were accessed.

TeamPCP, meanwhile, advertised roughly 450 repositories, about 5GB in total, for $25,000, and threatened to dump them for free if no buyer appeared within a week. One can therefore contend that this could be the same dump being remarketed by a different account, and the seller's profile is already suspect.

Are you a pro? Subscribe to our newsletter

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Contact me with news and offers from other Future brandsReceive email from us on behalf of our trusted partners or sponsors