A supply-chain attack on a single open-source package has cascaded into one of the messiest security incidents in the young AI industry, exposing data held by the data-labeling startup Mercor and forcing Meta to indefinitely pause its work with the company.
The breach, which Mercor confirmed on March 31, was traced to a compromise of LiteLLM, a widely used open-source tool downloaded millions of times daily. For roughly 40 minutes, a poisoned version of LiteLLM harbored credential-harvesting malware that stole login credentials and then used them to reach deeper into connected systems. The episode has since metastasized into lawsuits, a contracting freeze, and a broader reckoning over how much trust the AI industry places in intermediary software it does not control. For more breaking AI news on security and trust, follow our ongoing coverage.
How the Attack Worked
The mechanics are a textbook software supply-chain compromise. According to reporting by TechJuice and TechCrunch, attackers managed to push malicious code into LiteLLM, the open-source library that many AI companies use to route requests between different language models. Because LiteLLM is treated as trusted infrastructure and pulled into production environments automatically, the malicious build spread quickly.
For about 40 minutes, the tampered tool quietly harvested credentials from anyone running it. Those credentials were then used to access additional systems, compounding the damage beyond the initial foothold. Mercor, whose business depends on managing large volumes of sensitive contractor and client data, was among the most exposed.
A 4-Terabyte Extortion Claim
After the disclosure, a hacker group claimed to be holding roughly 4 terabytes of data stolen from Mercor's systems. The claimed haul includes candidate profiles, personally identifiable information, employer data, source code, and API keys, a sweeping inventory of exactly the kind of material a data-labeling company centralizes. Mercor has neither confirmed nor denied the authenticity of the claimed data, saying only that it is investigating.
The ambiguity is itself a problem. For the contractors, employers, and partners whose information may be circulating, the uncertainty about what was actually taken makes it impossible to assess their exposure.
Meta Pulls Back
The commercial fallout has been swift. Meta has paused its contracts with Mercor indefinitely, a decision made more striking by the history between the two companies. According to TechJuice, Meta had continued working with Mercor even after spending $14.3 billion to acquire Mercor's rival Scale AI, a sign of how much it valued the relationship. That a breach routed through a third-party tool could sever such a tie underscores how brittle these vendor relationships have become.
OpenAI has confirmed that it is investigating its own exposure in the breach but, at the time of reporting, had not paused its Mercor contracts. Multiple other large model makers are reportedly weighing their relationships with the startup, though no further names have been confirmed publicly.
Lawsuits and Liability Questions
The legal consequences are gathering as quickly as the commercial ones. Five of Mercor's contractors have filed lawsuits over alleged personal data exposure. One lawsuit reviewed by TechCrunch named LiteLLM and the AI compliance startup Delve as co-defendants, on the grounds that LiteLLM had used Delve to obtain its security certifications. That linkage opens a thorny question about whether compliance providers bear responsibility when the tools they vouch for are later weaponized.
These suits could help define where liability lands when a breach is routed through open-source software, a question the AI industry has so far avoided answering.
The Industry's Underexamined Attack Surface
Security researchers say the deeper lesson is structural. The AI stack now depends on a web of trusted intermediary tools, routers, evaluators, compliance layers, and labeling platforms that sit between model providers and their customers. Each one is a potential choke point, and most receive far less scrutiny than the frontier models themselves.
LiteLLM is illustrative. It is downloaded millions of times a day, handles credentials by design, and runs inside the production environments of some of the best-funded companies on earth. Yet a 40-minute window of tampering was enough to turn it into a skeleton key. The sequence has put the entire AI supply chain under scrutiny, with researchers warning that trusted intermediary tools represent an attack surface the industry has systematically underexamined.
What Happens Next
The immediate questions are whether Mercor can verify the scope of the leak, whether more model makers will follow Meta in pulling back, and whether the LiteLLM and Delve lawsuits establish a precedent for third-party liability. Longer term, the incident is likely to accelerate calls for the AI industry to adopt the kind of software bills of materials and dependency-signing practices that more mature software sectors already rely on.
For now, the breach stands as a warning that the most dangerous vulnerabilities in AI may not live inside the models at all, but in the unglamorous plumbing that connects them.
Stay Ahead of AI
The security of the AI stack is becoming as consequential as the models themselves. Bookmark AI Buzz Wire for the latest AI developments and AI industry coverage.
Read more AI news →


