A $10 billion AI startup just got gutted because a security scanner was the entry point.. and their own developers reportedly handed production credentials to an AI chatbot.
Mercor trains AI models for OpenAI, Anthropic, and Google DeepMind. They manage 30,000+ contractors, process $2 million in daily payouts, and store recorded video interviews with face and voice data used for identity verification. Three 22-year-old college dropouts built it into a decacorn in two years. The data vault they were sitting on was one of the most sensitive in the entire AI ecosystem.
The attack chain is the part that gets worse every sentence.
TeamPCP compromised Trivy first. A security scanning tool made by Aqua Security. On March 19. Trivy has broad read access to every environment it scans by design, because that's how vulnerability scanners work. The credentials stolen from the security product were used to hijack LiteLLM, the open-source proxy that routes API calls to every major LLM provider. LiteLLM gets 3.4 million downloads per day.
The poisoned version was uploaded straight to PyPI with no corresponding GitHub release, no tag, no review. Version 1.82.8 embedded the payload in a .pth file, which Python executes automatically at startup. You didn't need to import LiteLLM. You didn't need to call it. The malware fired the second Python opened.
Three stages. Harvest every SSH key, cloud token, Kubernetes secret, crypto wallet, and .env file on the machine. Deploy privileged containers across every node in the cluster. Install a persistent backdoor waiting for instructions. The stolen data was encrypted with a hardcoded 4096-bit RSA key and exfiltrated to models.litellm[.]cloud, a domain built to look legitimate.
Mercor was downstream. Reports indicate their developers gave production credentials to Claude, an AI coding assistant, which was running with unrestricted system permissions. The compromised LiteLLM package came in through that pipeline. One poisoned dependency turned a $10 billion company's entire infrastructure into a credential harvesting operation.
The haul: 939GB of source code. 211GB of database records containing resumes and personal data. 3TB of stored files including video interviews, face scans, and KYC documents. Full access to their TailScale VPN. 4TB total. Lapsus$ is now auctioning it with a "make an offer" price tag.
The video interviews are the part that can never be undone. Faces and voices used for identity verification can generate deepfakes. Unlike passwords, biometrics cannot be reset. Thousands of doctors, lawyers, and engineers who signed up to train AI models just had their identities permanently compromised.
Every AI company shipping fast right now has the same dependency chain underneath it. Nobody chose to install LiteLLM on that developer's machine. It came in as a dependency of a dependency of a tool they didn't even know they had.
🚀 Want to start a career in cybersecurity but don’t know where to begin?
Cybersecurity Career Starter Certification (CCSC)
💥 100% FREE — no catch.
🎟️ Use code: START-CYBER-100
🎁 Plus, a special career-support gift inside the course
🔗 Enroll now
https://t.co/fABRHbgixP
🚨 How a Trusted Tool Became a Stealthy Threat Vector
Our latest Hack & Fix investigation breaks down the Notepad++ supply-chain attack that compromised the update process for months.
Full analysis on our blog: https://t.co/iTyB5DuHSd
⏰ ONLY 5 DAYS LEFT! ⏰
The 75% OFF XMAS-75 coupon for Hack & Fix Academy certifications is about to expire! 🚨
After that, prices go back to normal. No extensions.
👉 Enroll now: https://t.co/PYmzNwPzM0
#CyberSecurity#HackAndFix#OnlineLearning#CyberCareer#LimitedOffer
💙 Built for our community — not for spam
🎓 The Cybersecurity Career Starter Certification (CCSC) is now accessible using a special community-only coupon:
🎟️ START-CYBER-100
👉 Start here
https://t.co/fABRHbgixP
🚀 We’re Live on Discord! 🎉
Hack & Fix Academy is excited to announce the launch of our official Discord server.
💡 Join us today and be part of the Hack & Fix Academy community!
https://t.co/P7zFLMTr4q
#CyberSecurity#LearningCommunity#HackAndFixAcademy#DiscordCommunity
🚨 All Hack & Fix Academy courses are now 75% OFF!
Use code: 🎟️ XMAS-75 and grab every course at a huge discount:
Original $20 → $5
Original $99 → $24.75
⏳ Hurry—𝐨𝐟𝐟𝐞𝐫 𝐞𝐧𝐝𝐬 31 𝐉𝐚𝐧𝐮𝐚𝐫𝐲 2026!
https://t.co/PYmzNwPzM0
🚀 New Certification Courses Live!
Hack & Fix Academy just released:
🔐 Certified AI Security Specialist
🛡️ Certified Online Fraud Prevention Specialist
https://t.co/DhiRQgIRJE
#CyberSecurity#AISecurity#Certifications#HackAndFix
⏳ Only a few days remaining!
𝐂𝐞𝐫𝐭𝐢𝐟𝐢𝐞𝐝 𝐏𝐡𝐢𝐬𝐡𝐢𝐧𝐠 𝐏𝐫𝐞𝐯𝐞𝐧𝐭𝐢𝐧 𝐒𝐩𝐞𝐜𝐢𝐚𝐥𝐢𝐬𝐭 𝐜𝐨𝐮𝐫𝐬𝐞 𝐅𝐑𝐄𝐄
The promotion ends on 31 December 2025 — don’t wait!
🎟️ Use coupon code phishing-100 at checkout
https://t.co/sOygwc8che
🚨 Cryptocurrency is the financial backbone of modern cybercrime.
From ransomware and phishing to darknet marketplaces and fraud networks, threat actors rely on crypto to move money fast, across borders, and at scale.
📖 Read the full article here:
https://t.co/XhZYQCAe8C
Certified Phishing Prevention Specialist course is completely FREE throughout December.
Use the coupon code phishing-100 at checkout:
📷 https://t.co/sOygwc8che
🎃 Halloween Special at @hack_and_fix Academy! 👻
To celebrate, we’re offering a massive 85% OFF on all cybersecurity courses. 🕷️
🎁 Use coupon code HALLOHACK85 at checkout
🔗 Explore courses: https://t.co/PYmzNwQ7By
🚨 Stop threats before they strike — with Hack & Fix.
We uncover, investigate & eliminate digital threats: blockchain tracing, dark web OSINT, red teaming, pentesting & forensics.
📩 [email protected]
https://t.co/dBqZ61Jkpv