40 Minutes, 2,500 Companies, and 4 Terabytes of Mercor's Secrets
Everyone keeps saying the software supply chain is 'the new attack surface.' Wrong framing. It's not new. It's just that we finally have a body count big enough to make people care.
In March 2026, attackers slipped a compromised version of LiteLLM — the open-source AI gateway with roughly 97 million monthly downloads — onto its official PyPI location. Not a typosquat. Not a lookalike package with a sketchy name. The real thing, from the real place, where thousands of developers had every reason to trust it.
The extraction window was about 40 minutes. Forty minutes to harvest cloud keys, repo tokens, SSH keys, Kubernetes secrets, package-publishing credentials, environment variables, and AI provider keys from more than 2,500 organizations, according to CloudSEK. Hudson Rock independently confirmed the scope wasn't limited to one unlucky company — it spanned an entire ecosystem. Names surfaced in the exposed data include Microsoft, Amazon, Cisco, Samsung, and Salesforce.
Let that sink in. Forty minutes is shorter than most standups.
The Elephant in the Room
Here's what nobody wants to say out loud: rotating secrets after this isn't enough. Recorded Future's Insikt Group put it plainly —
<> A single stolen credential or trusted package compromise can cascade across software ecosystems and become an operational crisis, not just an IT issue./>
That's the real story. This wasn't a breach of a company. It was a breach of trust in a distribution channel that thousands of companies had quietly built their CI/CD pipelines around. You can rotate a cloud key in an afternoon. You cannot instantly audit every federated identity token, every CI runner, every artifact registry, and every deployment permission that touched a poisoned LiteLLM install during a 40-minute window. Most organizations won't even try. They'll rotate the obvious stuff, issue a press statement, and move on.
Mercor didn't get that luxury. The AI-training-data company — which counts OpenAI, Anthropic, Meta, and Google among its customers — disclosed roughly 4 terabytes of stolen data tied to this campaign. SecurityWeek linked the broader operation to a group called TeamPCP, with extortion pressure reminiscent of Lapsus$-style leak-site tactics. So now it's not just
