@mistralai/mistralai-gcp 1.7.3
Obfuscated credential stealer and dropper
preinstall setup.mjs bootstraps Bun runtimeGitHub/npm token regex harvesting
SHA-2566ad402b3bf448dfc35f03fbe94741ce100069b6cd1a358de8dbbcc65e0c0e035
Also flagged by osv (MAL-2026-3512: Malicious code in @mistralai/mistralai-gcp (npm)) +3 more.