Mercor Data Exfiltrated in LiteLLM Supply Chain Attack
Mercor, an AI recruiting and model-training platform used by OpenAI and others, confirmed a security incident linked to the LiteLLM open-source supply chain compromise. The LiteLLM project was breached via unauthorized PyPI package publishes, distributing malicious code. Mercor's investigation is ongoing, but the attacker group Lapsus$ claims to have stolen hundreds of gigabytes of Mercor data, including contractor and training information. This data could expose Mercor's AI model development assets and customer relationships, raising risks for firms relying on Mercor's services. Mercor has released a clean LiteLLM version and is working with forensic experts to contain the breach.