Mistral AIãšTanStackãSLSAèªèšŒãã«ãŠã§ã¢ã«ãããµãã©ã€ãã§ãŒã³æ»æãåãã
æ»æè ã¯ãPyPIäžã®å ¬åŒMistral AI Pythonããã±ãŒãžã«å ãããã®ä»æ°çŸãã®åºãå©çšãããŠããéçºè åãããã±ãŒãžã䟵害ããAIããã³æå·é貚éçºè ãšã³ã·ã¹ãã å šäœã«ããã£ãŠGitHubããŒã¯ã³ãã¯ã©ãŠãdentæ å ±ããã¹ã¯ãŒãä¿ç®¡åº«ãå±éºã«ããããã.
ããšã倿ãããã mistralai PyPI äºæ¬¡ãã€ããŒããããŠã³ããŒãã㊠83.142.209.194 ã« /tmp/transformers.pyz ãšçºè¡šããã
Microsoftã¯ãmistralai PyPIããã±ãŒãžv2.4.6ã®äŸµå®³ã«ã€ããŠèª¿æ»ããŠããŸããæ»æè ã¯mistralai/client/__init__.pyã«ã³ãŒããæ³šå ¥ããã€ã³ããŒãæã«å®è¡ãããhxxps://83[.]142[.]209[.]194/transformers.pyzã/tmp/transformers.pyzã«ããŠã³ããŒãããLinuxäžã§ç¬¬2段éã®ãã€ããŒããèµ·åããŸãã⊠pic.twitter.com/9Xfb07Hcia
â Microsoft Threat Intelligence (@MsftSecIntel) 2026幎5æ12æ¥
Â
ãã¡ã€ã«åã¯ãHugging Face瀟ãåºã䜿çšããŠããTransformers AIãã¬ãŒã ã¯ãŒã¯ãæš¡å£ããŠããããã¹ãã©ã«ã§ã®äžæ£è¡çºã¯ãç ç©¶è ãã¡ãããã»ã·ã£ã€ã»ãã«ãŒããšåŒã¶ãçµç¹çãªäœæŠã®äžç°ã§ããã.
ã»ãã¥ãªãã£ãã©ãããã©ãŒã ã®SafeDepã¯ å ±åãã ã5æ11æ¥ãã12æ¥ã®éã«ã170以äžã®ããã±ãŒãžã䟵害ããã404ã®æªæã®ããããŒãžã§ã³ãå ¬éããããš
ãã®æ»æã¯CVE-2026-45321ã«åé¡ãããCVSSã¹ã³ã¢ã¯9.6ã§ãæ·±å»åºŠã¯ãã¯ãªãã£ã«ã«ããšè©äŸ¡ãããŠããŸãã.
SLSAã®åºæä¿¡é Œã¢ãã«ã厩å£ãã
ãã®æ»æãæ§é çã«dentã®ãªããã®ãšãªã£ãŠããçç±ã¯ãæªæã®ããããã±ãŒãžãæå¹ãªSLSAãã«ãã¬ãã«3ã®åºæèšŒæãä¿æããŠããç¹ã«ããã.
SLSAããããã³ã¹ã¯ãããã±ãŒãžãä¿¡é Œã§ãããœãŒã¹ãããã«ããããããšãæ€èšŒããããã«ãSigstoreã«ãã£ãŠçæãããæå·èšŒææžã§ãã.
Snykã¯ã TanStackæ»æã¯æå¹ãªSLSAæ¥æŽãæã€æªæã®ããnpmããã±ãŒãžãèšé²ãããæåã®äºäŸã§ãããèªèšŒããŒã¹ã®ãµãã©ã€ãã§ãŒã³é²åŸ¡ãæããã«äžååã§ããããšãæå³ãããšå ±åããã
TeamPCPãšdentãããæ»æè ã¯ã3ã€ã®è匱æ§ãé£éçã«å©çšãããå ·äœçã«ã¯ãpull_request_targetã¯ãŒã¯ãããŒã®èšå®ãã¹ãGitHub Actionsã®ãã£ãã·ã¥ãã€ãºãã³ã°ããããŠGitHub Actionsã©ã³ããŒããã»ã¹ããã®OIDCããŒã¯ã³ã®ã©ã³ã¿ã€ã ã¡ã¢ãªtracã§ããã.
æªæã®ããã³ãããã¯ãdentAnthropic Claude GitHub App ãè£
ã£ã [skip ci] ã
ãã«ãŠã§ã¢ãçããã®ãšãã®æ¡æ£æ¹æ³
ããã« Cryptopolitan å ±ãã 2026幎1æã«çºçããã850äžãã«ã®æå€±ã«ã€ãªãã£ãTrust Walletã®äºä»¶dent ãShai-Huludã¯ãŒã ã¯2025幎9æä»¥éãè€æ°ã®æ³¢ãçµãŠé²åãç¶ããŠããã
ãã®ææ°ã®äºçš®ã§ã¯ãã¹ã¯ãŒãä¿ç®¡åº«ã®ç飿©èœã远å ãããŠããã Wizã®ç ç©¶è ã㯠ããã®ãã«ãŠã§ã¢ãSSHããŒãAWSããã³GCPã®èªèšŒæ å ±ãKubernetesãµãŒãã¹ã¢ã«ãŠã³ããGitHubããŒã¯ã³ãnpmå ¬éèªèšŒæ å ±ã«å ããŠã1PasswordãšBitwardenã®ä¿ç®¡åº«ãæšçã«ããŠããããšãèšé²dentãŠdentã
çªçç¯ã¯ãã¿ã€ãã¹ã¯ã¯ããã£ã³ã°ãã¡ã€ã³ïŒgit-tanstack.comïŒã忣åã»ãã·ã§ã³ã¡ãã»ã³ãžã£ãŒãããã¯ãŒã¯ãããã³çãã ããŒã¯ã³ã§äœæããããã¥ãŒã³ãããŒãã«ããGitHubãªããžããªãšããã3ã€ã®åé·ãªçµè·¯ãéããŠè³éãæµåºãããã.
ãã·ã¢èªã®èšå®ãæ€åºããããšããã«ãŠã§ã¢ã¯çµäºããŸããã€ã¹ã©ãšã«ãŸãã¯ã€ã©ã³ã«å°ççã«äœçœ®ä»ããããã·ã¹ãã ã§ã¯ã6 åã® 1 ã®ç¢ºçã§ååž°çã¯ã€ã (rm -rf /) ãå®è¡ãããŸãã
ãã¹ãã©ã«ãšããåºç¯ãªçæ ç³»ã¯ã©ã®ããã«åå¿ããã
ãã¹ãã©ã«ç€Ÿã¯ ã»ãã¥ãªãã£å§å ãå瀟ã¯ã tracãã®ã€ã³ã·ãã³ãã®dent ãããåºç¯ãªTanStackãµãã©ã€ãã§ãŒã³ãã£ã³ããŒã³ã«é¢é£ããã䟵害ãããéçºè ããã€ã¹ã«
mistralai==2.4.6 ãªãªãŒã¹ã¯ãPyPI ããããžã§ã¯ããéé¢ããçŽåã® 5 æ 12 æ¥åå 12 æ UTC çŽåŸã«ã¢ããããŒããããŸããã.
ãªã©ã®äŸµå®³ããã npm ããã±ãŒãžã¯ã @mistralai/mistralaiã@mistralai/mistralai-azureã@mistralai/mistralai-gcpåé€ããããŸã§æ°æéã«ããã£ãŠå©çšå¯èœã§ããã
䟵害ãããããã±ãŒãžã®çޝèšé±éããŠã³ããŒãæ°ã¯5å1800äžãè¶ ããŠããŸãã@tanstack/react-routerã ãã§ããé±éããŠã³ããŒãæ°ã¯1270äžåã«éããŸãã.
圱é¿ãåããããŒãžã§ã³ãã€ã³ã¹ããŒã«ããéçºè
ã¯ãã¯ã©ãŠãèªèšŒæ
å ±ãGitHubããŒã¯ã³ãSSHããŒãããŒããŒã·ã§ã³ãdentAPIããŒã亀æãã .claude/ ããã³ .vscode/ ãã£ã¬ã¯ããªã«æ°žç¶åããã¯ããªããæ€æ»ããããšããå§ãããŸãã
ãã®èšäºãèªãã§ããããªãã¯ãæ¢ã«äžæ©å ãè¡ã£ãŠããŸãã ãã¥ãŒã¹ã¬ã¿ãŒã賌èªããŠããã®åªäœæ§ãç¶æããŸãããã
ããããèšäº














ã³ã¡ã³ã (0)
$ãã¿ã³ãã¯ãªãã¯ããã·ã³ãã«ãå ¥åããŠãæ ªåŒãETFããŸãã¯ãã®ä»ã®ãã£ãã«ãŒã·ã³ãã«ããªã³ã¯ããŸãã