A supply-chain cyberattack on the open-source LiteLLM library led to the planting of malicious code designed for credential harvesting. This incident resulted in a significant data breach at AI startup Mercor, potentially exposing sensitive company data, user information, and confidential AI project details.
Why This Matters
Publisher reporting describes a concrete security event. BugSkan could not yet bind it to a CVE or affected version, so treat the source details as the current record.
Recommended Action
Read the linked source. Identify named vendors, products, or environments and check whether they overlap with yours. Do not wait for a CVE if the report already describes exploitation or a vendor response.