Skip to content

LiteLLM · 2026-03

Mercor supply-chain breach

A 10 billion dollar AI startup was breached through the LiteLLM supply-chain attack, with 4 TB claimed stolen.

Last updated 2026-03
Could not check

What the sources report

The sources report a breach of a 10 billion dollar AI startup.

The route in was the LiteLLM supply-chain attack.

The claim is 4 TB stolen.

Root cause class

Supply chain

Covered by

What ShipReady can say

Where a dependency came from is not visible from a public URL. Provenance belongs in the Release Gate checklist.

Sources

Related incidents

  • Could not check

    Slopsquatting campaign on npm

    126 malicious npm packages exploited AI-hallucinated package names.

Check your app

Run all sixteen groups on your published address and see the evidence behind every result.

Running it confirms you own this app or are authorized to test it. ShipReady reads its public pages and JavaScript bundles.

ShipReady is not a penetration test or a security certification. No automated check can prove an application is secure.

Last updated September 20, 2026