Mercor Confirms Breach Linked to Open-Source LiteLLM Project Compromise
Key point
AI hiring startup **Mercor** confirmed damage from a cyberattack stemming from a supply chain attack on the open-source **LiteLLM** project.
Details
AI hiring startup Mercor confirmed a security incident linked to a supply chain attack on the open-source project LiteLLM. Mercor stated that this incident was one of thousands of companies affected by the recent compromise of the LiteLLM project, which has been connected to the TeamPCP hacking group.
The hacking group Lapsus$ claimed to have attacked Mercor and gained access to data, releasing Slack data, ticketing data, and sample videos containing conversations between Mercor's AI systems and contractors.
Mercor took immediate action to contain and remediate the security incident, and is currently conducting a thorough investigation together with professional forensic experts.
LiteLLM, the source of this incident, is a widely used library with millions of downloads daily, and malicious code was discovered in it last week. Following this incident, LiteLLM has switched partners to Vanta to strengthen its security compliance process.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.