How a Python Package Took Down a $10 Billion Startup
TeamPCP compromised Trivy, injected malware into LiteLLM on PyPI, and Lapsus$ walked away with 4TB of Mercor's data. Meta suspended the partnership. Mandiant says 1,000+ SaaS environments were hit.