Mercor AI — Cyber Attacks, Breaches & Threat Activity

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
April 1, 2026
Last Seen
June 18, 2026

Mercor AI is a organization tracked across 3 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed April 1, 2026; most recent activity June 18, 2026.

Related Threat Clusters

  • Mercor Cyberattack Linked to LiteLLM Supply Chain Compromise

    AI recruiting startup Mercor confirmed it was impacted by a supply chain attack linked to the LiteLLM project, which has affected thousands of organizations. The breach was attributed to the hacking group TeamPCP, with…

    30 articles · Updated April 1, 2026
  • PCPJack Malware Targets TeamPCP Victims for Credential Theft

    The newly discovered PCPJack malware framework is actively targeting cloud environments to steal credentials while removing remnants of the TeamPCP cybercrime group. This worm exploits exposed services such as Docker,…

    11 articles · Updated May 7, 2026
  • TeamPCP Exploits Trust in Open-Source Software and AI Tools

    In a span of four months, the threat actor TeamPCP has compromised over 1,000 open-source software packages, injecting malicious code and exploiting the trust developers place in these resources. The attack method…

    7 articles · Updated June 19, 2026

Recent Intelligence Reports

  • How software development’s speed obsession enabled TeamPCP’s chaos crusade — Cyberscoop · June 18, 2026
  • Cloud Credential Worm 'PCPJack' Targets TeamPCP Victims — Technadu · May 8, 2026
  • Mercor AI Cyberattack Tied to LiteLLM Project Compromise, Lapsus$ Claims Breach — Technadu · April 1, 2026

CVSS v3.1 Breakdown