on (#75JC2)
Microsoft says attackers compromised the mistralai PyPI package with malware that executed on import, while researchers link related npm compromises affecting TanStack and Mistral SDKs to the broader Mini Shai-Hulud" supply-chain campaign.