# Mistral AI Denies New Breach, But That "Fresh" Source Code Dump Looks Familiarly Stale

**A cybercrime forum seller claims to have hacked French AI giant Mistral again, offering the company's full source code for sale. But the cybersecurity community is skeptical—the "proof" looks suspiciously like the remnants of May's infamous TeamPCP supply chain attack.**

In the constantly shifting landscape of cybersecurity threats, a new claim has emerged that mirrors a familiar story. A seller operating under the handle "mrwho" posted on September 16, 2026, advertising "Selling mistral.ai Source Code" on an English-language cybercrime forum. The listing, which demands payment in Monero and directs potential buyers to Session or Telegram, has been swiftly refuted by Mistral AI's internal security team. However, the timing, the credentials of the seller, and the sample files provided are raising more questions than answers within the security research community. Is this a genuine second hacking incident, or is it simply a brazen attempt to resell data that has been on the market for months?

## The Claim: A Second Breach, or a Scam in the Making?

According to a report from The CyberSec Guru, the September listing is specific in its claims, offering what appears to be a trove of internal source code. The choice of Monero—a privacy-focused cryptocurrency—and the insistence on moving communications to encrypted platforms like Session or Telegram are standard operational security tactics for cybercriminals. However, the profile of the seller "mrwho" paints a conflicting picture. The account, created in September 2026, boasts a mere four posts and a reputation score of just 30. Despite this low activity, the account displays a top-tier "GOD User" rank, a badge usually reserved for trusted or long-standing members of such forums.

This discrepancy could indicate a scammer who purchased a high-level account to lend credibility to a fraudulent listing. Alternatively, as The CyberSec Guru notes, it could be a "front" for the original attackers using a fresh alias to avoid detection, or a broker trying to move stolen goods without drawing attention to the original source. For now, the veil of anonymity makes it impossible to discern the seller's true intent, but the data they are offering paints a picture that security researchers are all too familiar with.

## Deja Vu: Connecting the Dots to the May 2026 TeamPCP Attack

To understand why this claim is being met with extreme skepticism, we must rewind to May 2026. Mistral AI's previous hacking incident is undisputed. In what was dubbed the "Mini Shai-Hulud" supply chain campaign, the threat group known as TeamPCP executed a devastating attack that began with compromised TanStack packages and rapidly expanded to hundreds of npm and PyPI projects.

According to Mistral's own security advisory (MAI-2026-002), an automated worm led to the publication of compromised versions of its Software Development Kits (SDKs) for a few hours on May 11 and 12. The root cause involved an affected developer device. Microsoft Threat Intelligence tracked the attack vector, finding that a poisoned Mistral AI Python package fetched a second-stage credential stealer, enabling the attackers to exploit users further.

In statements to reporters, Mistral went deeper than the advisory. They told BleepingComputer that attackers had compromised a *codebase management system* and "contaminated some of our SDK packages for a brief period," though they insisted that hosted services, managed user data, and research environments remained untouched. More tellingly, the company informed HackRead that only specific non-core repositories were accessed.

The scale of the May breach was significant. TeamPCP advertised roughly 450 repositories—totaling about 5GB of data—for $25,000. The group threatened to dump the entire trove for free if no buyer surfaced within a week. This is the critical context for the current "mrwho" listing.

## The Evidence: Overlapping Files and Inconsistencies

The core question now is whether "mrwho" is selling a second, newer hack or attempting to remarket the TeamPCP dump. Initial analysis suggests the latter. HackRead previously published 24 sample repository names from TeamPCP's May post. When the FrenchBreaches security outlet examined the 339-file tree that "mrwho" shared in September, they found several of the same names appearing in both listings.

Notably, at least four specific repositories appear in both the May dump and the September listing: - `mistral-inference-private` - `mistral-inference-internal` - `mistral-finetune-internal` - `mistral-common-internal`

This overlap makes it challenging to determine whether the purported 'hack' is merely a rehash of an existing dump. The presence of these specific internal repositories suggests that "mrwho" likely has access to the same data that TeamPCP possessed. If this is the case, this is not a new security failure or vulnerability, but rather a public relations headache for Mistral as cybercriminals attempt to monetize an already "dead" dataset.

## The Litmus Test for a Genuine Security Failure

There is, however, a straightforward test to determine the truth of this alleged breach. Security researchers looking to validate the claim would need to examine the September archives for specific indicators of newness. If the archives contain commits, files, or embedded credentials dated *after* May 12, 2026, or if they contain secrets that were still valid after Mistral's cleanup efforts, the seller's claim of a second breach would gain significant weight. If everything in the archive predates the May incident, this is undeniably a resale.

Unfortunately, verifying these details is nearly impossible without paying the ransom. The requirement to pay in cryptocurrency for archives that might just be a rehash is a "tremendous leap of faith," especially for an account created just weeks ago. For any security researcher attempting to take a closer look, purchasing the dump based on the "GOD User" rank of a stranger is essentially a lottery ticket at best.

## What This Means for the Cybersecurity Landscape

For the readers of Hacker Pranks, this situation serves as a masterclass in cybercrime economics. The marketplace for stolen data is often inefficient, and the same data can circulate for months or years, changing hands multiple times as different actors try to profit from it. The May attack was a significant supply chain vulnerability that demonstrated the dangers of open-source dependencies and the speed of automated worms in the AI development ecosystem.

Now, the September "resale" highlights a second layer of the problem: verification. In the cybersecurity world, the line between a genuine zero-day exploit and a sophisticated scam is often blurred by hype and fear. While Mistral faces embarrassment and potential reputational damage from the resale of its internal code, the fact that they have stated they found "no evidence to support this claim" suggests that their infrastructure has not been re-comprised.

## Conclusion: A Storm in a Teacup or a Credible Threat?

Until concrete evidence emerges—such as a full disclosure by the seller or a forensic analysis by a third-party security firm—the "mrwho" listing remains an anomaly. The data offered is undeniably Mistral's, but the "freshness" of that data is highly suspect. For now, this looks more like a criminal attempting to capitalize on the notoriety of the TeamPCP breach rather than a new, sophisticated cyber-attack.

For tech enthusiasts and security researchers, the takeaway is clear: always scrutinize the source, compare the artifacts, and remember that in the murky depths of the dark web, history often repeats itself with a new price tag. The story of Mistral’s source code highlights the enduring challenge of distinguishing between a genuine new vulnerability and the re-circulation of old, stale data in the cybersecurity ecosystem.