
The Mercor Breach: How a Poisoned Security Scanner Cascaded Through AI Infrastructure
A threat group compromised Trivy, used it to steal LiteLLM's PyPI credentials, and published poisoned packages that led to a 4TB data breach at Mercor. Here's how the cascading supply chain attack worked and what it means for AI infrastructure security.










