Hackers Spare Russian-Speaking Users, Set Their Sights on Israel and Iran
Microsoft’s Threat Intelligence unit has confirmed that the mistralai package on PyPI was compromised. The attackers pushed a malicious version — 2.4.6 — which, when imported on Linux machines, would automatically download an extra file and quietly run it in the background. That file was disguised as a Hugging Face Transformers library and acted as an info-stealer: grabbing logins, passwords, and access tokens. After shipping the stolen data to a command-and-control server, it scrubbed its tracks.
The malware authors threw in a few unusual checks. If the system’s locale was set to Russian, the main payload wouldn’t activate. That’s how the attackers avoided infecting users in Russia and neighboring countries — places where they’d face a higher risk of criminal charges. This kind of move isn’t exactly new, but here it’s implemented particularly cleanly: the virus just stops running, leaving barely a trace. Cyber threats just keep getting more sophisticated — recently, for example, the official website of the CPU-Z and HWMonitor dev got hit, with the original files swapped out for malicious ones.
An even weirder logic is baked in for devices tied to Israel or Iran. On those systems, there’s a certain chance that the command rm -rf / gets executed — wiping all data from the disk. No encryption, no ransom demand, just irreversible deletion. Microsoft ties this incident to a campaign called Shai-Hulud, which has been compromising trusted software supply chain packages since September 2025. Mistral AI itself says its own infrastructure wasn’t breached — the infection came from a developer’s machine as part of a wider attack on the TanStack platform.
The advice is standard but no less important for it: isolate any compromised Linux systems, block the related IP addresses, and rotate all passwords, tokens, and access keys. If you cloned a suspicious repo or ran the mistralai package version 2.4.6, the only reliable way to clean up is a full OS reinstall. The Mythos AI, designed to hunt for vulnerabilities, leaked online not too long ago — and there might just be traces of it here too.
Why do you think virus authors avoid infecting computers in Russian-speaking countries? Drop your thoughts in the comments.
-
AI Gone Rogue? Hacker Uses Claude Chatbot to Hack the Mexican Government -
Updated CPU-Z From the Official Site? Your Passwords Might Have Been Swiped by Hackers -
AI for Finding Vulnerabilities Leaked Online — And the Reason Wasn't Hackers -
After 12 Years, Xbox One Has Finally Been Hacked — Through a Flaw That Can’t Be Patched -
Stolen Rockstar Games Data Leaked Online After Hackers Fail to Secure Ransom
