Supply Chain Security

Mercor Hit by LiteLLM Supply Chain Attack

The AI recruiting firm is investigating the incident as Lapsus$ claimed the theft of 4TB of Mercor data.

Mercor hacked

AI recruiting firm Mercor has disclosed impact from the recent LiteLLM supply chain attack, after extortionists claimed the theft of 4 terabytes of data.

The LiteLLM incident occurred on March 27 and was the result of the Trivy supply chain attack that was mounted a week before.

“We believe that the compromise originated from the Trivy dependency used in our CI/CD security scanning workflow,” LiteLLM notes in its description of the incident.

Using a maintainer’s compromised credentials, the TeamPCP hacking group published two malicious LiteLLM PyPI package versions, namely 1.82.7 and 1.82.8, which were available for download for roughly 40 minutes.

LiteLLM is estimated to be present in 36% of cloud environments, and while the exposure window appears small, the malicious package versions were likely automatically downloaded by thousands, including Mercor.

“We recently identified that we were one of thousands of companies impacted by a supply chain attack involving LiteLLM,” the startup said on Wednesday.

Advertisement. Scroll to continue reading.

“Our security team moved promptly to contain and remediate the incident. We are conducting a thorough investigation supported by leading third-party forensics experts,” Mercor added.

While the company has not shared details on the impact, the Lapsus$ extortion group listed Mercor on its leak site on Monday, claiming the theft of over 4TB of data.

Lapsus$ is auctioning the information, which allegedly includes candidate profiles, personally identifiable information, employer data, user accounts and credentials, video interviews, proprietary information, source code, keys and secrets, and TailScale VPN data.

TeamPCP was recently reported to have partnered with Lapsus$ to monetize the data and access obtained as part of its broad supply chain campaign, and it is no surprise that the extortion group has listed Mercor on its leak site. However, the company has yet to confirm Lapsus$ claims.

SecurityWeek has emailed Mercor for a statement on the matter and will update this article if the company responds.

Related: Stolen Logins Are Fueling Everything From Ransomware to Nation-State Cyberattacks

Related: TeamPCP Moves From OSS to AWS Environments

Related: Axios NPM Package Breached in North Korean Supply Chain Attack

Related: Toy Giant Hasbro Hit by Cyberattack

Related Content

Artificial Intelligence

Researchers say the new ‘Cryptographic Context Injection’ technique conceals malicious instructions until they are decrypted inside a trusted execution environment.

Malware & Threats

Hackers pushed a poisoned arrayref version that added a dependency to fetch a malicious payload from a remote server.

Cybercrime

We all know they’re watching us. But we don’t know who they are, nor why nor how they are doing it.

Artificial Intelligence

Atalanta's Argo product is now being used to prove the resilience of Viasat’s satellite communications network.

Artificial Intelligence

The action taken by OpenAI comes in light of the Hugging Face incident and the discovery of the Astra model’s advanced capabilities. 

Artificial Intelligence

A cybersecurity advisory with technical details and recommendations has been written by the NSA, CISA and other agencies.

Data Breaches

The cybercrime gang has listed major companies such as Shell, Philips, Fiserv, Zebra, Mindray, and Largan Precision.

Data Breaches

The data breach was initially believed to affect roughly 350,000 people, but the HHS breach tracker shows a far bigger impact.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version