Compromised LLM gateway packages harvest credentials, leading to a downstream customer breach
- Organization
- LiteLLM and Mercor
- Date
- Scale
- two malicious package versions live on PyPI for roughly 40 minutes; credentials harvested from systems that installed them; a downstream breach affecting a limited subset of one company's registered experts
- Surface
- Pipeline
- Tools involved
- Package install
- Harm
- Credential exposure, Data exfiltration
- Who was harmed
- Both
- Reversible
- No
- Root cause
- Malicious tool supply chain
- Prevented by action governance
- No
- Last verified
On 24 March 2026 two malicious versions of LiteLLM, an open-source gateway that routes calls to language model providers, were published to PyPI. They were live from 10:39 UTC for approximately 40 minutes before being quarantined. The packages carried a credential stealer that harvested environment variables, SSH keys, cloud provider credentials, Kubernetes tokens and database passwords, encrypting and sending them to a domain unaffiliated with the project.
The publishing credentials were not stolen from LiteLLM directly. The compromise reached the project's release pipeline through Trivy, a security scanner used inside its own CI/CD workflow — a supply chain attack delivered through a supply chain security tool. Installations that pinned their dependencies, including the official proxy Docker image, were unaffected. LiteLLM removed the packages, rotated maintainer credentials, engaged forensic specialists, rebuilt its release pipeline and published a clean version with signed images.
Mercor, a company that matches domain experts to AI labs for training work, was breached in the same period through credentials attributable to the LiteLLM compromise. An extortion group claimed on a leak site to hold several terabytes of the company's data, and reporting in the days that followed carried that claim alongside figures for the number of people affected.
Those early figures did not survive the investigation. In its own account published on 25 June 2026, after the investigation closed, Mercor stated that of its nearly five million experts "only a very limited subset had sensitive information affected," that customer platforms were largely isolated from the breach, that no employees were affected, and that there was "no evidence that any of this data has been used fraudulently." Affected experts were notified in late June and offered identity protection. The scale recorded here follows the completed investigation rather than the initial leak-site claim.
Sources
- 1.Security Update: Suspected Supply Chain IncidentLiteLLM · Primary source
- 2.Mercor Data Breach: Investigation Findings and UpdatesMercor · Primary source
- 3.
Sources last verified on .