Meta has suspended its partnership with Mercor, a $10 billion AI data startup, after a supply chain attack exposed sensitive information, including personal data and training methodologies for large language models. The breach, carried out through a compromised version of the open-source LiteLLM, has prompted investigations into OpenAI and Anthropic and led to a class action lawsuit involving more than 40,000 people.
See also: Australia: Meta, TikTok, Snapchat and YouTube fail to comply with social media ban for children

The attack not only involved the theft of personal data but also possibly the plans to build some of the most powerful AI models. Meta’s indefinite suspension of its partnership with Mercor, a San Francisco-based company that creates custom training datasets for major AI companies, has caused significant concern in the industry, which has invested heavily in maintaining its proprietary methods.
Founded in 2023 by Brendan Foody, Adarsh Hiremath , and Surya Midha , Mercor employs a diverse network of professionals to create high-quality training data for AI labs. Its clients include Meta, OpenAI, Anthropic, and Google.
See also: Meta's judgment on child safety in the hands of two jurors

The attack on Mercor originated from a compromised CI/CD pipeline of LiteLLM, an open-source Python library widely used by developers. A threat group known as TeamPCP exploited this vulnerability by obtaining credentials from a LiteLLM maintainer and publishing malicious versions of the library to the Python package repository, PyPI. These infected packages were available for about 40 minutes before being removed.
The malicious payloads were sophisticated, with one version embedding malware directly into the library code and another using a configuration file that was triggered every time a Python process was started. Both variants were designed to collect sensitive information, including API keys and cloud credentials, by exporting data to an external server.
See also: Meta's smart glasses bring Gemini-style voice commands to Ray-Ban and Oakley

Mercor confirmed that it was among the many companies affected by the attack, which exposed approximately four terabytes of data, including significant amounts of source code and user databases.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
