Open Source Supply Chain Attack Hits AI Ecosystem: LiteLLM Compromise Leads to Mercor Data Breach
A cyberattack on AI hiring startup Mercor has been traced to a compromised version of LiteLLM, one of the most widely used open source AI infrastructure libraries. The incident is a sharp warning about the security posture of the rapidly growing ecosystem of AI tooling — where trust in open source packages is high and security scrutiny often isn't.