AI Unicorn Mercor Hacked: Open-Source Project LiteLLM Compromised by Malware

Mercor Confirms Supply Chain Attack Targeting Its Open-Source Project LiteLLM, an incident impacting downstream ecosystems involving thousands of enterprises, emerging as a significant recent risk event within AI infrastructure security.
The prominent AI recruitment firm Mercor, valued at $1 billion, disclosed on Tuesday that its core LiteLLM project was compromised by malicious code injection, with the attack attributed to the hacker group TeamPCP. Concurrently, the ransomware group Lapsus$ claimed responsibility for stealing Mercor's internal data, publicly releasing sample information that included Slack communications, ticket system screenshots, and recorded conversations from AI systems. Mercor has engaged third-party forensic experts to lead an investigation and has implemented immediate containment and remediation steps, though it has not yet directly commented on the specifics of Lapsus$'s ransom demands.
The vulnerability is centered on the widely adopted LiteLLM open-source library. The project, which sees millions of daily downloads, is designed to streamline API calls for developers to leading models like OpenAI and Anthropic. While the malicious code was detected and eradicated within hours, its extensive reach as a supply chain component has prompted a thorough industry reassessment of open-source tool compliance.
In response, LiteLLM has urgently transitioned its compliance certification to Vanta. As an industry leader, Mercor secured $350 million in its Series C funding and handles over $2 million in daily payment transactions. This security breach underscores the fragility of the AI sector's foundational security during rapid growth, becoming a critical factor influencing model training and talent acquisition cycles. The industry must urgently establish more robust monitoring frameworks for open-source components.
Related article
Swedish AI Startup Lovable Eyes $13.2 Billion Valuation After Major Funding Round
As AI-driven coding tools gain traction, Swedish startup Lovable has secured a major funding round. The company aims to raise $3 billion, potentially boosting its valuation to $13.2 billion—double the $6.6 billion recorded last December. Menlo Ventur
Google Tests Remy AI Agent for Gemini as Focus Shifts to User Control
According to Business Insider, Google is testing Remy, a new AI personal agent for Gemini. This tool aims to execute tasks on behalf of users, streamlining both professional workflows and daily routines.Currently, Remy is undergoing testing in an int
How to fix Core Web Vitals for better SEO rankings
Streamline Report Card Comments with AI ToolsIntroductionAI Tools for Generating Report Card CommentsMagic SchoolAlmanac AIChat GPTUsing Magic School to Generate Report Card CommentsLogging into Magic SchoolSelecting the Report Card Comments ToolCust
Related Special Topic Recommendations
Comments (0)
0/500

Mercor Confirms Supply Chain Attack Targeting Its Open-Source Project LiteLLM, an incident impacting downstream ecosystems involving thousands of enterprises, emerging as a significant recent risk event within AI infrastructure security.
The prominent AI recruitment firm Mercor, valued at $1 billion, disclosed on Tuesday that its core LiteLLM project was compromised by malicious code injection, with the attack attributed to the hacker group TeamPCP. Concurrently, the ransomware group Lapsus$ claimed responsibility for stealing Mercor's internal data, publicly releasing sample information that included Slack communications, ticket system screenshots, and recorded conversations from AI systems. Mercor has engaged third-party forensic experts to lead an investigation and has implemented immediate containment and remediation steps, though it has not yet directly commented on the specifics of Lapsus$'s ransom demands.
The vulnerability is centered on the widely adopted
In response, LiteLLM has urgently transitioned its compliance certification to Vanta. As an industry leader, Mercor secured $350 million in its Series C funding and handles over $2 million in daily payment transactions. This security breach underscores the fragility of the AI sector's foundational security during rapid growth, becoming a critical factor influencing model training and talent acquisition cycles. The industry must urgently establish more robust monitoring frameworks for open-source components.
Swedish AI Startup Lovable Eyes $13.2 Billion Valuation After Major Funding Round
As AI-driven coding tools gain traction, Swedish startup Lovable has secured a major funding round. The company aims to raise $3 billion, potentially boosting its valuation to $13.2 billion—double the $6.6 billion recorded last December. Menlo Ventur
How to fix Core Web Vitals for better SEO rankings
Streamline Report Card Comments with AI ToolsIntroductionAI Tools for Generating Report Card CommentsMagic SchoolAlmanac AIChat GPTUsing Magic School to Generate Report Card CommentsLogging into Magic SchoolSelecting the Report Card Comments ToolCust





Home






