Mercor, the high-profile AI recruiting startup valued at $10 billion, has confirmed it was a victim of a widespread supply chain attack involving the open-source library LiteLLM. The breach, which came to light following claims from the notorious extortion group Lapsus$, has put the privacy of thousands of job seekers and the security infrastructure of major AI developers at significant risk.
The LiteLLM Supply Chain Vulnerability
The incident originated from a sophisticated supply chain compromise targeting the LiteLLM library, a tool widely used to connect applications to various AI models. Security researchers at Snyk and Wiz identified that the hacking group TeamPCP gained unauthorized access to a maintainer’s credentials, allowing them to push two malicious versions of the LiteLLM package, 1.82.7 and 1.82.8, to the PyPI repository. These malicious files were available for download for approximately 40 minutes on March 27, during which time thousands of organizations—including Mercor—automatically pulled the compromised code into their production environments.
Stakes for the AI Ecosystem
The impact of this breach is substantial. Lapsus$, an extortion group known for high-profile corporate targeting, has claimed responsibility for the theft of over 4TB of internal data. The group has publicly listed Mercor on its leak site, alleging that the stolen trove includes candidate profiles, personally identifiable information, internal ticketing data, proprietary source code, and even video recordings of job interviews conducted through the Mercor platform. For a company that serves major industry players like OpenAI and Anthropic, the exposure of these credentials and secrets represents a critical failure in third-party dependency management.
Containment and Forensic Investigation
Mercor has acknowledged the breach, stating that its security team acted to contain and remediate the incident shortly after discovery. The company has engaged third-party forensics experts to conduct a comprehensive investigation into the extent of the data exfiltration. While Mercor has not yet officially verified the full scope of the Lapsus$ claims, the cybersecurity community remains on high alert. The attack underscores the inherent risks of modern CI/CD pipelines, where a single compromised dependency in an open-source library can grant attackers a foothold in even the most well-funded AI infrastructure.
The resurgence of Lapsus$ in this incident demonstrates that even unicorn-status AI firms are not immune to classic supply-chain exploitation, signaling a shift where attackers no longer need to breach a company directly, but rather exploit the foundational software libraries that the entire industry relies upon.

