AI firm Mercor confirmed a breach stemming from a supply chain attack involving the open-source LiteLLM PyPI package, where attackers published malicious versions after compromising maintainer credentials. This incident led to the alleged theft of 4TB of sensitive data, including candidate profiles, PII, source code, and API keys, subsequently listed by the Lapsus$ extortion group.
Why This Matters
Publisher reporting describes a concrete security event. BugSkan could not yet bind it to a CVE or affected version, so treat the source details as the current record.
Recommended Action
Read the linked source. Identify named vendors, products, or environments and check whether they overlap with yours. Do not wait for a CVE if the report already describes exploitation or a vendor response.