A sophisticated supply chain attack on the popular LiteLLM proxy system has hit Mercor and "thousands" of other companies. The incident underscores the critical vulnerability of AI infrastructure.
LiteLLM as Gateway
LiteLLM, a widely used proxy for various AI APIs, was compromised through manipulated dependencies. Attackers were able to:
- Steal API keys: Access to OpenAI, Anthropic, Google APIs
- Redirect requests: Manipulation of AI responses
- Billing fraud: Unauthorized AI usage at the victims' expense
"One of Thousands" Affected
Mercor CEO confirms: "We are just one of thousands of affected companies." The statement suggests a broadly coordinated campaign against the AI supply chain.
The attack reveals the critical dependency of the AI industry on open-source components and proxy services. Many startups and companies use LiteLLM to optimize costs and implement multi-provider setups.
Security experts warn of a new class of supply chain attacks specifically targeting AI infrastructure. The high API costs and sensitive data make AI services lucrative targets for cybercriminals.
Source: The Register 02.04.2026