Threat IntelHIGH

Mercor Confirms Security Incident from LiteLLM Supply Chain Attack, Data Stolen

Featured image for Mercor Confirms Security Incident from LiteLLM Supply Chain Attack, Data Stolen
TRThe Record+1 more
LiteLLMTeamPCPLapsus$Mercorsupply chain attackcybersecuritydata breach
🎯

Mercor, a company that helps other businesses find AI experts, has admitted that it was hit by a big cyberattack that affected many companies. Hackers stole a lot of important data from them, and now they're trying to figure out how to fix the problem and keep their customers safe.

Quick Summary

Mercor confirms it was impacted by the LiteLLM supply chain attack, with significant data theft reported by the extortion group Lapsus$.

Mercor, an AI recruiting startup, has confirmed that it was impacted by the recent LiteLLM supply chain attack, marking it as one of the first downstream victims to publicly acknowledge the incident. The company stated on social media that it was 'one of thousands of companies' affected, emphasizing the widespread nature of the attack. Mercor is known for its collaborations with major firms like OpenAI and was valued at $10 billion as of October 2025.

In a statement, Mercor spokesperson Heidi Hagberg reiterated the company's commitment to customer privacy and security, stating, 'Our security team moved promptly to contain and remediate the incident.' The firm is currently conducting a thorough investigation with the assistance of third-party forensics experts.

The attack has been linked to the hacking group TeamPCP, while the notorious extortion group Lapsus$ claimed responsibility for stealing approximately 4 terabytes of data from Mercor, including 939 gigabytes of source code. They have reportedly offered the stolen data for sale to the highest bidder. While Mercor has not disclosed how Lapsus$ accessed its data, security researchers from Wiz have indicated that high-profile extortion groups are now collaborating with TeamPCP, which has been implicated in multiple supply chain attacks.

The ramifications of the LiteLLM attack are extensive, with estimates suggesting that as many as 500,000 machines may have been compromised. Experts predict that the number of downstream victims could rise significantly, with Mandiant Consulting's CTO indicating that over 1,000 SaaS environments are actively dealing with the fallout. As the investigation unfolds, it is clear that Mercor's incident is part of a larger pattern of supply chain vulnerabilities affecting the tech industry.

The ongoing collaboration between TeamPCP and extortion groups like Lapsus$ highlights a concerning trend in cybercrime, where supply chain vulnerabilities are exploited to gain access to sensitive data across multiple organizations. As the situation evolves, companies must enhance their security protocols to mitigate the risk of similar attacks.

Original article from

TRThe Record
Read Full Article

Also covered by

THThe Register Security

AI recruiting biz Mercor says it was 'one of thousands' hit in LiteLLM supply-chain attack

Read Article

Related Pings

HIGHThreat Intel

Supply Chain Attack - Axios npm Package Compromised

A major supply chain attack targeted the Axios npm package, affecting millions of applications. Malicious versions were published, risking user data and system integrity. Organizations must act quickly to mitigate the impact and secure their environments.

Arctic Wolf Blog·
HIGHThreat Intel

STARDUST CHOLLIMA - Compromises Axios npm Package

A serious security breach has compromised the Axios npm package, affecting countless developers. This incident highlights the vulnerabilities in software supply chains, especially for cryptocurrency users. Action is needed to safeguard against these sophisticated attacks.

CrowdStrike Blog·
HIGHThreat Intel

Axios Supply Chain Attack - How It Was Detected

A major supply chain attack on Axios was detected using a proof of concept tool. This incident highlights vulnerabilities in package management systems and the need for better security measures. Swift action was taken to mitigate the damage and protect users.

Elastic Security Labs·
HIGHThreat Intel

Axios npm Supply Chain Attack - Mitigation Steps Explained

Axios experienced a serious supply chain attack linked to North Korea's Sapphire Sleet. Countless users who downloaded the malicious npm packages are at risk. Immediate actions are necessary to secure affected systems and prevent further exploitation.

Microsoft Security Blog·
HIGHThreat Intel

Iran Cyber Campaign - North Korea Targets Axios NPM Package

Iran's cyber campaign intensifies, targeting U.S. interests. North Korea compromises the Axios NPM package, raising serious supply chain concerns. Organizations must act swiftly to bolster defenses.

CyberWire Daily·
HIGHThreat Intel

Axios Supply Chain Attack - Widespread Impact Revealed

A recent supply chain attack on Axios has led to the deployment of malware across multiple sectors. This incident affects businesses globally, emphasizing the critical need for immediate security measures. Stay informed and protect your systems from potential exploitation.

Palo Alto Unit 42·