Mercor confirms security incident tied to LiteLLM supply chain attack
嗯,用户让我帮忙总结一下这篇文章的内容,控制在一百个字以内,而且不需要用“文章内容总结”之类的开头,直接写描述。好的,我先仔细看看这篇文章。 文章讲的是一个平台Mercor,帮助AI行业领袖改进他们的模型。最近发生了安全事件,是供应链攻击导致的。Mercor是受害者之一,被攻击的是开源项目LiteLLM。Mercor是一个很受欢迎的招聘公司,和OpenAI等合作,培训AI模型。他们被攻击后,发言人Heidi Hagberg表示客户隐私和安全很重要,已经采取措施应对。现在他们正在调查中,并且有外部专家帮忙。 还有提到黑客组织Lapsus$声称获得了大量数据,但发言人没回应这个问题。LiteLLM上周确认了攻击,并发布了一个干净版本。TechCrunch最先报道了这个事件。 好,我需要把这些信息浓缩到100字以内。重点包括:Mercor确认安全事件,供应链攻击影响 LiteLLM;Mercor与OpenAI合作;发言人回应; LiteLLM发布修复版本;Lapsus$声称获取数据。 可能的结构:Mercor因供应链攻击导致安全事件影响LiteLLM;公司回应并调查; LiteLLM修复版本发布;Lapsus$声称获取数据。 检查字数:确保不超过100字。 </think> AI行业平台Mercor因供应链攻击导致安全事件影响开源项目LiteLLM。公司迅速采取措施并展开调查, LiteLLM已发布修复版本。黑客组织Lapsus$声称获取大量数据。 2026-4-1 19:15:42 Author: therecord.media(查看原文) 阅读量:17 收藏

A platform that helps AI industry leaders improve their models on Wednesday confirmed a security incident tied to a recent supply chain attack.

The startup, Mercor, was one of thousands of firms to be impacted by the security compromise of the open-source effort LiteLLM, according to a company statement.

Mercor is a popular recruiting outfit that works with  companies including OpenAI to hire experts and train AI models. As of October 2025, the company was reportedly valued at $10 billion.

“The privacy and security of our customers and contractors is foundational to everything we do at Mercor,” Mercor spokesperson Heidi Hagberg said in a statement. “Our security team moved promptly to contain and remediate the incident.” 

Mercor is conducting an investigation with the help of outside forensics experts, the statement added.

TechCrunch was first to report Mercor’s confirmation of the security incident.

Although the LiteLLM attack was reportedly tied to a group called TeamPCP, the hacking gang Lapsus$ claimed on its website that it obtained hundreds of gigabytes of Mercor’s data.

Hagberg did not immediately respond to questions about Lapsus$’s claims.

LiteLLM confirmed the hack on its systems last week, saying it was “investigating a suspected supply chain attack involving unauthorized PyPI package publishes.” The open-source project said evidence indicated that a user’s PyPI account may have been “compromised and used to distribute malicious code.”

A clean version of LiteLLM was released Monday, according to a LiteLLM security post.

Jonathan Greig contributed reporting.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.


文章来源: https://therecord.media/mercor-confirms-security-incident-tied-to-litellm
如有侵权请联系:admin#unsafe.sh