AI recruiting biz Mercor says it was 'one of thousands' hit in LiteLLM supply-chain attack

2026-04-02T07:23:55Zfc153f2e2863e53cc8ced27ce9cc0721f4bdc5507c6bb825a368cfa3b219ed75
axioschatgpt-dns-leakcitrix-netscalercloud-infectioncredential-stealerdownstream-compromiseextortionin-the-wild-exploitationlapsus$litellmmalwarenpmopenaipypisoftware-supply-chainsupply-chaintelnyxtrivy

What happened

Multiple large-scale supply‑chain compromises and follow-on infections reported. The Trivy CI/CD compromise injected credential‑stealing malware into downstream projects (notably LiteLLM), with malicious PyPI and npm packages (LiteLLM, Telnyx, and tainted Axios releases) used to seed developer machines and cloud workloads; researchers say over 1,000 cloud environments have been infected and victims include commercial downstreams such as AI hiring startup Mercor. Attackers are leveraging stolen secrets with extortion crews (e.g., Lapsus$) and continuing to poison open‑source ecosystems. Related

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
theregister_security
Record identifier
fc153f2e2863e53cc8ced27ce9cc0721f4bdc5507c6bb825a368cfa3b219ed75
Enrichment time
2026-04-02T07:23:55Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.