Mercor supply-chain breach
A 10 billion dollar AI startup was breached through the LiteLLM supply-chain attack, with 4 TB claimed stolen.
npm · 2026-02
126 malicious npm packages exploited AI-hallucinated package names.
The sources report 126 malicious npm packages exploiting AI-hallucinated package names.
A USENIX study of 2.23 million samples found 19.7 percent referenced a package that did not exist.
Supply chain
A URL check reads a published app, not its dependency tree. Dependency scanning belongs to the platform and to the Release Gate checklist.
A 10 billion dollar AI startup was breached through the LiteLLM supply-chain attack, with 4 TB claimed stolen.
Run all sixteen groups on your published address and see the evidence behind every result.
ShipReady is not a penetration test or a security certification. No automated check can prove an application is secure.
Last updated September 20, 2026