Mercor says it was hit by cyberattack tied to compromise of open-source LiteLLM project
ID: 1bf79de7-538c-55da-a87e-f3891699fee2
STIX ID: report--1bf79de7-538c-55da-a87e-f3891699fee2
Feed Name: TechCrunch Security News
Mercor, an AI recruiting startup, confirmed it was impacted by a supply-chain compromise of the open-source LiteLLM project tied to a group called TeamPCP; extortion group Lapsus$ also claimed it accessed and leaked Mercor data. Malicious code was found in a LiteLLM package and removed within hours, but the library's widespread use raises concerns about scale and exposure; Mercor says it is containing the incident and working with third-party forensics while investigations continue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
