Observed Signal · Apr 1, 2026 · Security Incident · Source: techcrunch · Impact: 4/5 · Sentiment: Negative

Mercor Hit by LiteLLM Supply-Chain Cyberattack

Executive Signal Summary

Mercor, an AI recruiting startup, confirmed a security incident tied to a supply-chain compromise of the open-source LiteLLM project. The compromise has been linked to a hacking group called TeamPCP, and extortion group Lapsus$ has claimed it targeted Mercor and posted a sample of purportedly stolen data. Mercor said it is one of “thousands of companies” affected, has engaged third-party forensics, and is communicating with customers and contractors. LiteLLM’s maintainers removed malicious code from a package within hours; security firm Snyk reported the library is widely used and downloaded millions of times per day. Mercor — founded in 2023, a partner to OpenAI and Anthropic — was valued at $10 billion after a $350 million Series C led by Felicis Ventures in October 2025. Investigations into the scope and any data exposure remain ongoing.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

A supply-chain compromise of a widely used open-source LLM library can affect thousands of organizations, threaten model training pipelines and contractor/customer data, and raises systemic security risks across AI and related infrastructure.

SIGNAL RADAR

Track LiteLLM Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • Mercor confirmed a security incident linked to a supply-chain compromise of the open-source LiteLLM project.
  • Security researchers connected the LiteLLM compromise to a hacking group referred to as TeamPCP.
  • Extortion group Lapsus$ claimed it targeted Mercor and published a sample of alleged stolen data including Slack and ticketing material.
  • LiteLLM maintainers removed malicious code from a compromised package within hours; security firm Snyk reported the library is downloaded millions of times per day.
  • Mercor was valued at $10 billion after a $350 million Series C round led by Felicis Ventures in October 2025 and said it facilitates more than $2 million in daily payouts.

Ontology Mapping & Concepts

Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: techcrunch•Published: Apr 1, 2026
Original Coverage Title: “Mercor says it was hit by cyberattack tied to compromise of open-source LiteLLM project | TechCrunch”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

Large Language Models (LLM) & AIApr 9, 2026

Data Breach Hits $10B AI Training Startup Mercor

Mercor, an AI data‑training startup valued at $10 billion after a $350 million Series C, disclosed on March 31 that it was the target of a data breach. A hacker group claimed to have stolen roughly 4TB of data, reportedly including candidate profiles, personally identifiable information, employer data, source code and API keys. Mercor says the breach stemmed from a supply‑chain compromise of the popular open‑source tool LiteLLM, which hosted credential‑harvesting malware for about 40 minutes. Following the disclosure, Meta reportedly paused contracts with Mercor; OpenAI said it is investigating but had not paused contracts. Several contractors have filed lawsuits alleging personal data exposure. The incident also touches third parties: LiteLLM dropped its security vendor Delve after whistleblower allegations about Delve’s certification practices, and Delve has faced operational fallout including Y Combinator severing ties.

Read assessment
Large Language Models (LLM) & AIMar 26, 2026

LiteLLM Malware Exposes Delve Compliance Claims

A severe supply‑chain malware infection was discovered in LiteLLM, a popular open‑source project that provides unified access to many AI models. Research scientist Callum McMahon of FutureSearch found the malware after his machine shut down following a LiteLLM download; the malicious code entered via a dependency, stole login credentials and propagated to other packages. Security firm Snyk reported LiteLLM downloads as high as 3.4 million per day and noted the project had ~40K GitHub stars. LiteLLM displayed SOC 2 and ISO 27001 certifications obtained through Delve, an AI‑powered compliance startup now accused elsewhere of misleading customers about conformity (Delve denies the allegations). LiteLLM says it is investigating with Mandiant and performing a forensic review; CEO Krrish Dholakia declined to comment on Delve’s role. The incident highlights risks in dependency management and limits of certification-based assurances.

Read assessment
FundraisingJul 9, 2026

Mercor in Talks for $20B Valuation

AI training startup Mercor is reportedly in early-stage talks to raise a funding round valuing the company at $20 billion, according to Bloomberg. That would double the $10 billion valuation Mercor achieved in October after a $350 million Series C. Mercor says it has received a term sheet at the new valuation and CEO Brendan Foody has posted that the company’s annualized revenue run rate (ARR) crossed $2 billion, a 100% increase in four months. Separately, Mercor announced the acquisition of Deeptune, whose team will join Mercor. The company previously faced a data breach and contractor lawsuits in early 2026. Sources and specifics remain limited as discussions are described as being at an early stage.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.