AI startup Mercor confirms security incident linked to LiteLLM supply chain attack | brief | SC Media
The incident stems from a supply chain attack targeting the open-source LiteLLM project, where malicious code was injected. This compromise led to thousands of organizations, including AI startup Mercor, suffering data breaches and exfiltration of sensitive information.
STABLE
What Happened
The incident stems from a supply chain attack targeting the open-source LiteLLM project, where malicious code was injected. This compromise led to thousands of organizations, including AI startup Mercor, suffering data breaches and exfiltration of sensitive information.
Why This Matters
Publisher reporting describes a security event affecting Mercor. BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.
Recommended Action
Confirm whether Mercor is present in your environment and review vendor guidance for this report. Apply available patches or mitigations if your deployment matches the described conditions.
Exposure
Exposure unknown
Apr 01, 2026 05:30
Exposure reason: This incident does not currently match a technology in My Interests.
Exploitation status: UNKNOWN
Primary entities:
Timeline
-
Incident first seen
Apr 01, 2026 05:30BugSkan first recorded this incident.
-
AI startup Mercor confirms security incident linked to LiteLLM supply chain attack | brief | SC Media - SC Media
Apr 01, 2026 05:30scworld.com ยท Vulnerability
-
Mercor says it was hit by cyberattack tied to compromise of open source LiteLLM project - TechCrunch
Apr 01, 2026 05:30techcrunch.com ยท Data Leak
Sources
scworld.com ยท Apr 01, 2026 05:30
The incident stems from a supply chain attack targeting the open-source LiteLLM project, where malicious code was injected. This compromise led to thousands of organizations, including AI startup Mercor, suffering data breaches and exfiltration of sensitive information.
Open publisher sourcetechcrunch.com ยท Apr 01, 2026 05:30
Mercor, an AI recruiting startup, experienced a data breach following a supply chain attack on the open-source LiteLLM project, which involved the injection of malicious code into its packages. The Lapsus$ hacking group claimed responsibility for targeting Mercor and exfiltrating sensitive data, including Slack and ticketing information, as evidenced by shared samples.
Open publisher sourceRelated Incidents
Other BugSkan incidents that share identifiers, products, or vendors with this report.
My Interests Match
Create an account to see which incidents overlap with your interests.