TL;DR: A cascading supply chain attack, starting with a compromised security scanner called Trivy, jumping to the Python AI library LiteLLM, and landing in the systems of $10 billion AI hiring startup Mercor, resulted in 4 terabytes of stolen data. That includes video interviews, passport scans, Social Security numbers, and proprietary AI training methodologies belonging to 40,000+ contractors who worked for companies like Meta, OpenAI, and Anthropic. Meta froze all Mercor contracts. Five lawsuits have been filed. The stolen data is being auctioned on the dark web. And the fake compliance company that certified Mercor's security just got kicked out of Y Combinator.
One Poisoned Update, Five Ecosystems Down
The attack didn't start at Mercor. It started at Aqua Security's Trivy: an open-source vulnerability scanner used by thousands of companies to find security problems. The irony is brutal.
Here's how the chain unraveled, step by step [1][2]:
Late February 2026: Trivy Gets Compromised
A threat group called TeamPCP exploited a pull_request_target workflow vulnerability in Trivy's GitHub Actions. That gave them maintainer credentials. On March 19, they rewrote Trivy's GitHub Action v0.69.4 with credential-harvesting payloads [2].
A security tool turned into a weapon. Nobody noticed for days.
March 24: LiteLLM Gets Poisoned
LiteLLM is a Python library that lets developers connect to 100+ large language model providers through a single API. It has roughly 95 million monthly downloads, 40,000 GitHub stars, and sits inside an estimated 36% of all cloud environments [2]. Its whole purpose is holding API keys for dozens of AI providers.
At 10:39 UTC on March 24, LiteLLM's CI/CD pipeline ran the compromised Trivy action. TeamPCP grabbed the PYPI_PUBLISH token. Within thirteen minutes, they'd published two malicious LiteLLM versions (1.82.7 and 1.82.8) to PyPI, the Python package repository [1].
The malicious code swept everything it could find: SSH keys, cloud credentials for AWS, Google Cloud, and Azure, Kubernetes secrets, cryptocurrency wallets, API keys, and database credentials. Version 1.82.8 used .pth file injection for persistence. It would survive reboots and run across all Python interpreters on the machine [2].
Detection: 40 Minutes Too Late
Security researcher Callum McMahon noticed when his machine crashed around 11:48 UTC. PyPI quarantined LiteLLM by 13:38 UTC [2]. The malicious packages were live for roughly 40 minutes to 3 hours, depending on when systems pulled the update.
Three hours. Across 3.4 million daily downloads.
Mandiant CTO Charles Carmakal estimated over 1,000 SaaS environments faced cascading effects, with potential expansion to 10,000+ [2]. Security intelligence group vx-underground put the estimate higher: exfiltration from 500,000 machines [2].
What Got Stolen From Mercor
Mercor is a San Francisco AI startup valued at $10 billion. It hires, vets, and manages contractors who do AI training work (labeling data, running evaluations, building training datasets) for companies like Meta, OpenAI, and Anthropic [3][4].
That means Mercor holds incredibly sensitive data about the people doing AI's grunt work. When TeamPCP (operating under the Lapsus$ banner) got in, they took everything [3][4]:
- 939 GB of platform source code: Mercor's entire codebase
- 211 GB user database: personal details of contractors and clients
- ~3 TB of video interview recordings and identity verification documents: passport scans, driver's licenses, W-9 forms
- 40,000+ contractors' Social Security numbers
- Internal Slack messages, ticketing data, and TailScale VPN configurations
- Proprietary AI training methodologies from frontier AI labs: data selection criteria, labeling protocols, training strategies that companies spent years and billions developing [4]
Four terabytes, total. Listed for auction on dark web forums.
Why AI Companies Are Panicking
The SSNs and passport scans are a privacy catastrophe for the 40,000+ affected workers. But for the AI industry, the AI training data is the nightmare.
Mercor's contractors weren't just filing paperwork. They were building the training pipelines for frontier AI models. The stolen data potentially includes how OpenAI selects training data, how Anthropic labels outputs for safety, how Meta structures reinforcement learning from human feedback [4].
This isn't public information. These methodologies are trade secrets, the actual competitive advantage behind billions of dollars in AI development. And now they're on a dark web auction block.
Meta's response: freeze everything. The company indefinitely suspended all Mercor contracts. Contractors can't log hours. Internal sources told The Next Web that Meta is scrambling to find alternative projects for affected workers [4]. Meta's AI capital expenditures are projected at $115-135 billion this year. Protecting that training pipeline is existential.
OpenAI said it's "investigating but continuing current Mercor projects." Anthropic and Google gave no public comment on their exposure [4].
The Compliance Firm Was Fake
It gets worse.
Delve Technologies, the GRC startup that certified LiteLLM's SOC 2 and ISO 27001 compliance, was exposed as running "fake compliance as a service" [2].
An analysis of 494 leaked SOC 2 reports from Delve revealed 99.8% identical text across different clients. Pre-written sections existed in reports before clients even submitted their system descriptions. Over 99% of clients were audited by overseas certification mills operating as fronts. Delve's platform auto-generated passing evidence for security tasks that employees hadn't actually completed [2].
Delve was founded by MIT dropouts in 2023, raised $32 million at a $300 million valuation, and got kicked out of Y Combinator on April 4, 2026 [2].
So the tool that was supposed to catch security problems (Trivy) became the attack vector. And the company that was supposed to certify security compliance (Delve) was rubber-stamping fake audits. Two layers of trust. Both broken.
The Legal Fallout
Five lawsuits hit Mercor within the first week [5][2]:
- Gill v. Mercor.io (N.D. Cal., filed April 1): alleges failure to implement multi-factor authentication, encrypt sensitive data, or monitor systems
- Deboni v. Mercor.io: filed simultaneously with Gill
- Esson v. Mercor: alleges breach of implied duty of care
- Two additional suits name BerriAI (LiteLLM's parent company) and Delve Technologies as co-defendants
The Gill complaint is particularly damning: no MFA, unencrypted sensitive data, inadequate access controls, insufficient system monitoring, and infrequent password rotation [5]. For a $10 billion company handling Social Security numbers and passport scans.
Plaintiffs are seeking compensatory and punitive damages, court-ordered security overhauls, credit monitoring services, annual security audits, and mandatory third-party security reviews [5].
The Supply Chain Cascade Nobody Predicted
This attack exposes a terrifying reality: the AI industry is built on a house of open-source cards.
The same Trivy compromise that breached the European Commission (340GB from 71 EU entities) also led to the LiteLLM poisoning that hit Mercor [2]. One GitHub Actions vulnerability. Two major breaches. Entirely different victims.
LiteLLM isn't some obscure library. ARMO Security put it bluntly: "LiteLLM isn't just any Python library. Its entire purpose is to hold API keys for dozens of AI providers" [2]. With 240+ million Docker pulls and integration into major frameworks like CrewAI and DSPy, it's plumbing that most AI developers never think about, until it explodes.
Suzu Labs Senior Director Jacob Krell captured the scale: "One dependency. One chain reaction. Five supply chain ecosystems compromised in under a month" [2].
The Axios npm supply chain attack by North Korea's UNC1069 hit the JavaScript ecosystem the same week. Open-source software isn't just a convenience for attackers. It's become the preferred attack surface.
What Affected Workers Should Do Now
Freeze Your Credit, Today
Your SSN was stolen. Call Equifax (800-685-1111), Experian (888-397-3742), and TransUnion (888-909-8872) to place a credit freeze. It's free and prevents anyone from opening accounts in your name.
File an IRS Identity Protection PIN
With your SSN in criminal hands, tax fraud is a real risk. Get an IP PIN at irs.gov/identity-theft-fraud-scams/get-an-identity-protection-pin to prevent someone from filing a tax return in your name.
Monitor for Identity Fraud
Passport scans and W-9s were stolen. Monitor your bank accounts, credit reports (AnnualCreditReport.com is free), and any accounts linked to the email you used with Mercor. Set up transaction alerts on every financial account.
Document Everything for the Lawsuit
If you were a Mercor contractor, save any communications from Mercor about the breach. You may be eligible to join the class action. Five suits are already filed in Northern District of California.
When the AI Industry's Shortcuts Come Home
Mercor raised $10 billion in valuation. It couldn't be bothered to implement multi-factor authentication for systems holding 40,000 people's Social Security numbers.
LiteLLM processed 95 million monthly downloads. Its compliance certification came from a company that copy-pasted the same report for 99.8% of its clients.
The AI industry moves fast. It moves fast past security. Past encryption. Past the idea that maybe, just maybe, when you're storing video interviews, passport scans, and SSNs for tens of thousands of workers, you should have more than the bare minimum protecting them.
The workers who got breached aren't AI executives. They're contractors. Gig workers. The people doing the labeling and training that AI companies need to build their products but don't want to hire full-time. They handed over their most sensitive documents to get work. Now those documents are for sale.
And the chain reaction isn't over. Over 1,000 SaaS environments hit. Potentially 500,000 machines compromised. All from one poisoned update to a security scanner.
The next time someone tells you open-source software is inherently secure because "many eyes make all bugs shallow," ask them about the thirteen minutes between LiteLLM getting poisoned and the malicious packages going live. Ask them about the 40 minutes before anyone noticed. Ask them about the four terabytes of stolen lives sitting on a dark web auction block right now.
References
- TechCrunch: Mercor says it was hit by cyberattack tied to compromise of open source LiteLLM project (March 31, 2026)
- StrikeGraph: The Mercor breach exposed Silicon Valley's fragile AI supply chain (April 2026)
- Fortune: Mercor, a $10 billion AI startup, confirms it was the victim of a major cybersecurity breach (April 2, 2026)
- The Next Web: Meta freezes AI data work after breach puts training secrets at risk (April 2026)
- ClaimDepot: Mercor class action alleges AI startup failed to protect data of more than 40,000 people (April 2026)