Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
package-repository-poisoningcredential-stealer-activitythird-party-vendor-breachdata-exfiltration-method

Mercor Breach Traced to Malicious LiteLLM Packages in Supply-Chain Attack

Updated 17d agoFirst seen Apr 1, 20264 sources

AI recruiting firm Mercor confirmed a security incident after attackers leveraged the LiteLLM supply-chain compromise to gain access to its environment. Reports said unauthorized publishes to the project's PyPI packages introduced credential-stealing malware designed to harvest API keys, cloud secrets, and tokens from organizations using the open-source LLM gateway. Mercor said it was among thousands of organizations affected, contained and remediated the issue, and brought in external forensic experts as the investigation continued; LiteLLM separately said it was investigating the malicious package activity and released a clean version of the software.

Security reporting identified Mercor as the first publicly confirmed downstream victim of the campaign, with stolen credentials allegedly used for lateral movement inside internal infrastructure and the exfiltration of roughly 4 TB of data. The reportedly stolen data included source code, internal databases, and cloud-stored operational material such as videos and verification workflows. Researchers linked the incident to a broader wave of poisoned developer-tool compromises, including Trivy and KICS, and warned that related attacks may have impacted more than 1,000 SaaS environments and potentially hundreds of thousands of machines; separate claims by Lapsus$ and reporting tying the operation to TeamPCP remained unresolved in the cited coverage.

Share:
Mercor Breach Traced to Malicious LiteLLM Packages in Supply-Chain Attack
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Apr 1, 20263mo ago

Reports detail Mercor data theft and lateral movement

Subsequent reporting said malicious LiteLLM packages stole credentials that were used to access Mercor's internal infrastructure, move laterally, and exfiltrate about 4 terabytes of data including source code, databases, and operational datasets. Separate reporting also noted claims that Mercor data had been obtained by attackers, which Mercor had not addressed at the time.

Mercor confirms security incident tied to LiteLLM supply chain attack | The Record from Recorded Future News

Mercor confirms security incident tied to LiteLLM compromise

Mercor confirmed it was affected by the LiteLLM supply-chain attack and said its security team moved quickly to contain and remediate the issue while an investigation continued with external forensic experts. Reporting described Mercor as the first publicly identified confirmed downstream victim.

Mercor confirms security incident tied to LiteLLM supply chain attack | The Record from Recorded Future News

LiteLLM releases a clean software version

LiteLLM released a clean version of its software after the malicious package issue was identified. The release was described as occurring on Monday.

Mercor confirms security incident tied to LiteLLM supply chain attack | The Record from Recorded Future News

LiteLLM discloses investigation into unauthorized PyPI publishes

LiteLLM said it was investigating unauthorized package publishes on PyPI and that a compromised user PyPI account may have been used to distribute malicious code.

Mercor confirms security incident tied to LiteLLM supply chain attack | The Record from Recorded Future News
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

11 LINKEDOpen in app
Threat actors
2 linked
Affected products
3 linked
LitellmLitellmTrivy
Organizations
5 linked
MercorY CombinatorLitellmTechCrunchOpenai
Breaches
1 linked
MERCOR-2026-04
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.