MIT TRACE

MIT CTL Logo
Back to Main Dashboard

LiteLLM PyPI supply-chain compromise propagates to Mercor

On 24 March 2026 attackers hijacked LiteLLM publishing access and released malicious versions 1.82.7 and 1.82.8 through PyPI. The packages contained credential-stealing malware; Mercor later confirmed that it installed an affected LiteLLM version, experienced unauthorized activity and identified sensitive information belonging to a subset of its experts as affected.

76

Estimated severity

76 / 100

92

Source reliability

92 / 100

Approximate Date

24/03/2026

Targeted Company

BERRIAI

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

MERCOR (Software vendor)

Geographic Impact

Country Targeted Company

Country visual unavailable

No information

Other Affected Countries

No other affected countries reported

Target country

No information

Affected countries

No information

Impacted regions

No information

Operational Impact

Duration

No information

Financial impact (USD M)

No information

Impact types

Supply chain data integrity impactDownstream customer disruption

Affected sectors

Technology & IT ServicesProfessional & Business Services

Affected departments

Information Technology

Attack Profile

Attack types

Software supply chain compromiseMalwareUse of stolen credentials

Attributed threat actors

TEAMPCP

Sources

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.