HomeSecurityMercor hit by supply chain attack related to LiteLLM

Mercor hit by supply chain attack related to LiteLLM

A recent cyberattack on Mercor has once again brought the risks associated with open-source software dependencies. The company confirmed that it was affected by a broader supply chain breach, which is still under investigation and has been linked to a malicious incident involving the widely used LiteLLM project.

Mercor

LiteLLM is an open-source project widely used in the AI ​​ecosystem. Mercor acknowledged that it was “one of thousands of companies” affected by the breach, which has been attributed to a hacking group known as TeamPCP.

Supply chain attacks

This cyberattack highlights the growing threat of supply chain attacks, where hackers infiltrate widely used software components to gain access to multiple targets simultaneously.

See also: What the Kash Patel email breach really means

The situation became more complicated when the hacking group Lapsus$claimed responsibility for targeting Mercor and accessing its data. However, it remains unclear how Lapsus$ obtained the information or whether it directly exploited the LiteLLM vulnerability. The lack of clarity creates even greater uncertainty about the scope and impact of the incident.

Mercor: A few words about the victim

Founded in 2023, Mercor is a key player in the AI ​​talent ecosystem. The company partners with major AI companies, including OpenAI and Anthropic, to help models machine learning. It does this by connecting organizations with skilled professionals like scientists, doctors, and lawyers, many of whom are located in global markets like India.

Mercor hit by supply chain attack related to LiteLLM

The trajectory is remarkable, with the company reaching a $10 billion valuation after a $350 million Series C funding round in October 2025. This scale makes the data breach at Mercor particularly significant, as any service outage or data exposure could potentially impact a large network of users and partners.

Reaction to Cyberattack

Mercor spokeswoman Heidi Hagbergsaid the organization acted quickly to contain the issue. She noted that the company “acted immediately” to address the incident and limit its potential impact.

See also: Google attributes Axios Supply Chain Attack to UNC1069

“We are conducting a thorough investigation with the support of leading independent experts. We will continue to communicate with our customers and contractors as appropriate and will dedicate the necessary resources to resolving the issue as soon as possible.”

This reaction indicates that Mercor is treating the data breach as an emergency, although specific details about the extent of the breach or the type of data that may have been exposed have not yet been disclosed.

Origin of the LiteLLM Security Incident

As previously reported, the breach was caused by a cyber incident in the LiteLLM project, when malicious code was discovered in one of its packages. The issue came to light last week and was addressed within hours of its detection. Despite the immediate response, the incident raised concerns due to the widespread adoption of LiteLLM. According to security firm Snyk, LiteLLM is downloaded millions of times a day, making it a critical component in many AI workflows.

See also: Trivy supply chain attack: Cisco source code theft

Mercor hit by supply chain attack related to LiteLLM

The scale of its use means that even a brief breach could have far-reaching consequences, as demonstrated by the Mercor cyberattack and similar incidents affecting other organizations. Following the incident, LiteLLM initiated changes to its compliance and security processes. One notable adjustment included moving compliance certifications from Delve to Vanta, in an effort to strengthen oversight and restore trust.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Despite the available information, several key questions about the Mercor breach remain unanswered. It is also still unclear how many companies were affected by the LiteLLM breach or whether any sensitive data was definitively exposed in its case.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS