Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
AI Firm Mercor Affected by LiteLLM Supply Chain Breach

AI Firm Mercor Affected by LiteLLM Supply Chain Breach

Posted on April 2, 2026 By CWS

AI recruitment company Mercor has recently revealed its involvement in the LiteLLM supply chain breach, during which attackers claimed to have stolen 4 terabytes of sensitive data. This breach, part of the broader Trivy supply chain attack, occurred on March 27.

Details of the LiteLLM Breach

The origin of the LiteLLM incident is linked to the Trivy dependency used in LiteLLM’s continuous integration and continuous deployment (CI/CD) security processes. According to LiteLLM, compromised credentials allowed the TeamPCP hacking group to release two malicious versions of the LiteLLM PyPI package, specifically 1.82.7 and 1.82.8, which were available for download for a brief period of 40 minutes.

Despite the short window, the packages were likely downloaded by numerous users, including Mercor, as LiteLLM is integrated into 36% of cloud environments worldwide.

Mercor’s Response and Investigation

Mercor confirmed its status among the many companies affected by the supply chain attack involving LiteLLM. In response, Mercor’s security team acted swiftly to contain and mitigate the incident. The company is currently conducting a comprehensive investigation with the aid of top forensic experts to understand the extent and implications of the breach.

While Mercor has not provided specific details regarding the impact, the Lapsus$ extortion group has listed Mercor on its leak site. They claim the stolen data includes candidate profiles, personal information, employer data, user credentials, video interviews, proprietary information, source code, and TailScale VPN details.

Collaboration Between TeamPCP and Lapsus$

Recent reports have highlighted a partnership between TeamPCP and Lapsus$, aimed at monetizing the data and access acquired through a widespread supply chain campaign. The appearance of Mercor on Lapsus$’s leak site aligns with this strategy, although Mercor has yet to officially confirm these claims.

Inquiries have been sent to Mercor for further comments on the situation, and updates will follow as more information becomes available.

For related news, consider reading about the rise of stolen logins fueling cyberattacks, TeamPCP’s transition from open-source software to AWS environments, and other recent high-profile cyber incidents.

Security Week News Tags:AI, CI/CD security, cloud environments, Cybersecurity, data breach, data theft, Extortion, forensics investigation, LAPSUS, LiteLLM, Mercor, PyPI packages, supply chain attack, TeamPCP, Trivy

Post navigation

Previous Post: WhatsApp Warns 200 Users of Fake iOS App Spyware
Next Post: Critical Cisco Flaw Allows Remote Command Execution

Related Posts

MCBS Cyberattack Exposes Data of Over 1.2 Million MCBS Cyberattack Exposes Data of Over 1.2 Million Security Week News
Webinar Today: Rethinking Endpoint Hardening for Today’s Attack Landscape Webinar Today: Rethinking Endpoint Hardening for Today’s Attack Landscape Security Week News
1.4 Million Affected by Data Breach at Virginia Radiology Practice 1.4 Million Affected by Data Breach at Virginia Radiology Practice Security Week News
eSIM Hack Allows for Cloning, Spying  eSIM Hack Allows for Cloning, Spying  Security Week News
France Says Administrator of Cybercrime Forum XSS Arrested in Ukraine France Says Administrator of Cybercrime Forum XSS Arrested in Ukraine Security Week News
Qualcomm Flags Exploitation of Adreno GPU Flaws, Urges OEMs to Patch Urgently Qualcomm Flags Exploitation of Adreno GPU Flaws, Urges OEMs to Patch Urgently Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • WordPress Backups Expose Valuable AWS and Email Credentials
  • Antino Backdoor Utilizes Microsoft 365 in Espionage
  • OpenClaw Unveils Free AI Agent Management Platform
  • Critical GitLab AI Gateway Vulnerability Patched
  • Critical cPanel/WHM Flaws Risk Server Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • WordPress Backups Expose Valuable AWS and Email Credentials
  • Antino Backdoor Utilizes Microsoft 365 in Espionage
  • OpenClaw Unveils Free AI Agent Management Platform
  • Critical GitLab AI Gateway Vulnerability Patched
  • Critical cPanel/WHM Flaws Risk Server Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark