Compromised LLM gateway packages harvest credentials, leading to a downstream customer breach

Organization
LiteLLM and Mercor
Date
Scale
two malicious package versions live on PyPI for roughly 40 minutes; credentials harvested from systems that installed them; a downstream breach affecting a limited subset of one company's registered experts
Surface
Pipeline
Tools involved
Package install
Harm
Credential exposure, Data exfiltration
Who was harmed
Both
Reversible
No
Root cause
Malicious tool supply chain
Prevented by action governance
No
Last verified

On 24 March 2026 two malicious versions of LiteLLM, an open-source gateway that routes calls to language model providers, were published to PyPI. They were live from 10:39 UTC for approximately 40 minutes before being quarantined. The packages carried a credential stealer that harvested environment variables, SSH keys, cloud provider credentials, Kubernetes tokens and database passwords, encrypting and sending them to a domain unaffiliated with the project.

The publishing credentials were not stolen from LiteLLM directly. The compromise reached the project's release pipeline through Trivy, a security scanner used inside its own CI/CD workflow — a supply chain attack delivered through a supply chain security tool. Installations that pinned their dependencies, including the official proxy Docker image, were unaffected. LiteLLM removed the packages, rotated maintainer credentials, engaged forensic specialists, rebuilt its release pipeline and published a clean version with signed images.

Mercor, a company that matches domain experts to AI labs for training work, was breached in the same period through credentials attributable to the LiteLLM compromise. An extortion group claimed on a leak site to hold several terabytes of the company's data, and reporting in the days that followed carried that claim alongside figures for the number of people affected.

Those early figures did not survive the investigation. In its own account published on 25 June 2026, after the investigation closed, Mercor stated that of its nearly five million experts "only a very limited subset had sensitive information affected," that customer platforms were largely isolated from the breach, that no employees were affected, and that there was "no evidence that any of this data has been used fraudulently." Affected experts were notified in late June and offered identity protection. The scale recorded here follows the completed investigation rather than the initial leak-site claim.

Sources

  1. 1.
    Security Update: Suspected Supply Chain Incident
    LiteLLM · Primary source
  2. 2.
    Mercor Data Breach: Investigation Findings and Updates
    Mercor · Primary source
  3. 3.

Sources last verified on .