Country visual unavailable
No information
On 24 March 2026 attackers hijacked LiteLLM publishing access and released malicious versions 1.82.7 and 1.82.8 through PyPI. The packages contained credential-stealing malware; Mercor later confirmed that it installed an affected LiteLLM version, experienced unauthorized activity and identified sensitive information belonging to a subset of its experts as affected.
Estimated severity
76 / 100
Source reliability
92 / 100
Approximate Date
24/03/2026
Targeted Company
BERRIAI
Distribution & Fulfillment
Procurement & Sourcing
Production & Manufacturing
Sales (Retail & Ecommerce)
Warehousing
Service Delivery
Unrecognized Impact
Supply Chain Relations
Country visual unavailable
No information
No other affected countries reported
Target country
No information
Affected countries
No information
Impacted regions
No information
Duration
No information
Financial impact (USD M)
No information
Impact types
Affected sectors
Affected departments
Attack types
Attributed threat actors
Please rotate your phone