Mercor confirms security incident tied to LiteLLM supply chain attack
ID: 8272c64e-b137-5c3f-9291-f4e9b597ea5b
STIX ID: report--8272c64e-b137-5c3f-9291-f4e9b597ea5b
Feed Name: The Record from Recorded Future News
Threat Score
LiteLLM confirmed a suspected supply-chain attack involving unauthorized PyPI package publishes that distributed malicious code; the compromise affected thousands of firms and prompted a clean release. Mercor — an AI recruiting and model-training company — confirmed it was impacted, is investigating with outside forensics, and faces claims from Lapsus$ that hundreds of gigabytes of its data were exfiltrated.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
