Last seen April 1, 2026

AI startup Mercor confirms security incident linked to LiteLLM supply chain attack | brief | SC Media

The incident stems from a supply chain attack targeting the open-source LiteLLM project, where malicious code was injected. This compromise led to thousands of organizations, including AI startup Mercor, suffering data breaches and exfiltration of sensitive information.

Technical Severity
Low severity
Lifecycle Status

STABLE

What Happened

The incident stems from a supply chain attack targeting the open-source LiteLLM project, where malicious code was injected. This compromise led to thousands of organizations, including AI startup Mercor, suffering data breaches and exfiltration of sensitive information.

Why This Matters

Publisher reporting describes a security event affecting Mercor. BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.

Recommended Action

Confirm whether Mercor is present in your environment and review vendor guidance for this report. Apply available patches or mitigations if your deployment matches the described conditions.

Exposure

My Interests Exposure

Exposure unknown

Recommended Response
Last Seen

Apr 01, 2026 05:30

Exposure reason: This incident does not currently match a technology in My Interests.

Exploitation status: UNKNOWN

Primary entities:

LiteLLMData LeakageRemote Code ExecutionSupply ChainMercorSC Media

Timeline

  • Incident first seen
    Apr 01, 2026 05:30

    BugSkan first recorded this incident.

  • AI startup Mercor confirms security incident linked to LiteLLM supply chain attack | brief | SC Media - SC Media
    Apr 01, 2026 05:30

    scworld.com ยท Vulnerability

  • Mercor says it was hit by cyberattack tied to compromise of open source LiteLLM project - TechCrunch
    Apr 01, 2026 05:30

    techcrunch.com ยท Data Leak

Sources

AI startup Mercor confirms security incident linked to LiteLLM supply chain attack | brief | SC Media - SC Media

scworld.com ยท Apr 01, 2026 05:30

The incident stems from a supply chain attack targeting the open-source LiteLLM project, where malicious code was injected. This compromise led to thousands of organizations, including AI startup Mercor, suffering data breaches and exfiltration of sensitive information.

Open publisher source
Mercor says it was hit by cyberattack tied to compromise of open source LiteLLM project - TechCrunch

techcrunch.com ยท Apr 01, 2026 05:30

Mercor, an AI recruiting startup, experienced a data breach following a supply chain attack on the open-source LiteLLM project, which involved the injection of malicious code into its packages. The Lapsus$ hacking group claimed responsibility for targeting Mercor and exfiltrating sensitive data, including Slack and ticketing information, as evidenced by shared samples.

Open publisher source

Other BugSkan incidents that share identifiers, products, or vendors with this report.

My Interests Match

Want personalized relevance?

Create an account to see which incidents overlap with your interests.

โ† Back to incident intelligence