logo

AI recruiting biz Mercor says it was 'one of thousands' hit in LiteLLM supply-chain attack

ID: 1188369f-8684-5a3b-9a76-01060716574d

STIX ID: report--1188369f-8684-5a3b-9a76-01060716574d

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2026-04-02

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

TeamPCP compromised popular open-source developer tools (including Trivy, KICS, and packages on PyPI such as LiteLLM), injecting credential-stealing malware that has been used to validate stolen secrets, move laterally, and exfiltrate large amounts of data; downstream victims include AI hiring startup Mercor which reportedly had source code stolen. The campaign is widespread and ongoing, with estimates of thousands to hundreds of thousands of impacted systems and active collaboration between TeamPCP and extortion/ransomware groups to monetize stolen data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.