Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
AI Firm Mercor Affected by LiteLLM Supply Chain Breach

AI Firm Mercor Affected by LiteLLM Supply Chain Breach

Posted on April 2, 2026 By CWS

AI recruitment company Mercor has recently revealed its involvement in the LiteLLM supply chain breach, during which attackers claimed to have stolen 4 terabytes of sensitive data. This breach, part of the broader Trivy supply chain attack, occurred on March 27.

Details of the LiteLLM Breach

The origin of the LiteLLM incident is linked to the Trivy dependency used in LiteLLM’s continuous integration and continuous deployment (CI/CD) security processes. According to LiteLLM, compromised credentials allowed the TeamPCP hacking group to release two malicious versions of the LiteLLM PyPI package, specifically 1.82.7 and 1.82.8, which were available for download for a brief period of 40 minutes.

Despite the short window, the packages were likely downloaded by numerous users, including Mercor, as LiteLLM is integrated into 36% of cloud environments worldwide.

Mercor’s Response and Investigation

Mercor confirmed its status among the many companies affected by the supply chain attack involving LiteLLM. In response, Mercor’s security team acted swiftly to contain and mitigate the incident. The company is currently conducting a comprehensive investigation with the aid of top forensic experts to understand the extent and implications of the breach.

While Mercor has not provided specific details regarding the impact, the Lapsus$ extortion group has listed Mercor on its leak site. They claim the stolen data includes candidate profiles, personal information, employer data, user credentials, video interviews, proprietary information, source code, and TailScale VPN details.

Collaboration Between TeamPCP and Lapsus$

Recent reports have highlighted a partnership between TeamPCP and Lapsus$, aimed at monetizing the data and access acquired through a widespread supply chain campaign. The appearance of Mercor on Lapsus$’s leak site aligns with this strategy, although Mercor has yet to officially confirm these claims.

Inquiries have been sent to Mercor for further comments on the situation, and updates will follow as more information becomes available.

For related news, consider reading about the rise of stolen logins fueling cyberattacks, TeamPCP’s transition from open-source software to AWS environments, and other recent high-profile cyber incidents.

Security Week News Tags:AI, CI/CD security, cloud environments, Cybersecurity, data breach, data theft, Extortion, forensics investigation, LAPSUS, LiteLLM, Mercor, PyPI packages, supply chain attack, TeamPCP, Trivy

Post navigation

Previous Post: WhatsApp Warns 200 Users of Fake iOS App Spyware
Next Post: Critical Cisco Flaw Allows Remote Command Execution

Related Posts

Chrome Sandbox Escape Earns Researcher 0,000 Chrome Sandbox Escape Earns Researcher $250,000 Security Week News
German Authorities Take Down Crypto Swapping Service eXch German Authorities Take Down Crypto Swapping Service eXch Security Week News
Vulnerability in Totolink Range Extender Allows Device Takeover Vulnerability in Totolink Range Extender Allows Device Takeover Security Week News
Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack Security Week News
Censys Secures M to Boost Internet Intelligence Censys Secures $70M to Boost Internet Intelligence Security Week News
New Sturnus Banking Trojan Targets WhatsApp, Telegram, Signal Messages New Sturnus Banking Trojan Targets WhatsApp, Telegram, Signal Messages Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cisco Addresses Critical Security Vulnerabilities
  • Trusted Open Source Insights: AI and Security Trends
  • Oracle Cuts Jobs to Boost AI Investment
  • Data Breach Affects 250,000 at Nacogdoches Hospital
  • Researchers Expose Cyber Scheme Using Fake Installers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cisco Addresses Critical Security Vulnerabilities
  • Trusted Open Source Insights: AI and Security Trends
  • Oracle Cuts Jobs to Boost AI Investment
  • Data Breach Affects 250,000 at Nacogdoches Hospital
  • Researchers Expose Cyber Scheme Using Fake Installers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark