AI recruiting firm Mercor confirmed a security incident after attackers leveraged the LiteLLM supply-chain compromise to gain access to its environment. Reports said unauthorized publishes to the project's PyPI packages introduced credential-stealing malware designed to harvest API keys, cloud secrets, and tokens from organizations using the open-source LLM gateway. Mercor said it was among thousands of organizations affected, contained and remediated the issue, and brought in external forensic experts as the investigation continued; LiteLLM separately said it was investigating the malicious package activity and released a clean version of the software.
Security reporting identified Mercor as the first publicly confirmed downstream victim of the campaign, with stolen credentials allegedly used for lateral movement inside internal infrastructure and the exfiltration of roughly 4 TB of data. The reportedly stolen data included source code, internal databases, and cloud-stored operational material such as videos and verification workflows. Researchers linked the incident to a broader wave of poisoned developer-tool compromises, including Trivy and KICS, and warned that related attacks may have impacted more than 1,000 SaaS environments and potentially hundreds of thousands of machines; separate claims by Lapsus$ and reporting tying the operation to TeamPCP remained unresolved in the cited coverage.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Subsequent reporting said malicious LiteLLM packages stole credentials that were used to access Mercor's internal infrastructure, move laterally, and exfiltrate about 4 terabytes of data including source code, databases, and operational datasets. Separate reporting also noted claims that Mercor data had been obtained by attackers, which Mercor had not addressed at the time.
Mercor confirmed it was affected by the LiteLLM supply-chain attack and said its security team moved quickly to contain and remediate the issue while an investigation continued with external forensic experts. Reporting described Mercor as the first publicly identified confirmed downstream victim.
LiteLLM released a clean version of its software after the malicious package issue was identified. The release was described as occurring on Monday.
LiteLLM said it was investigating unauthorized package publishes on PyPI and that a compromised user PyPI account may have been used to distribute malicious code.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
hackread.com
Open sourcebankinfosecurity.com
Open sourcegovinfosecurity.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.