tomspark wrote:
Mistral's security posture has been sketchy for a while, honestly. If this is real, it's not shocking — and the npm/PyPI angle is nasty because so many projects pull from those repos without thinking twice. Supply chain attacks are the move now.