AI Security · Supply Chain
Supply-Chain Malware in LiteLLM Harvests Cloud Credentials A malicious PyPI dependency in the open-source LiteLLM project installed credential-harvesting malware that collected environment variables, SSH keys and passwords. LiteLLM is widely adopted—Snyk reports up to 3.4 million downloads per day—so stolen credentials could expose cloud keys, API tokens and downstream packages. Investigators traced the publishes to a compromised maintainer account used in LiteLLM's pipeline and flagged a possible link to an earlier Trivy compromise.
1 source · Mar 31
Timeline Sources Mar 31 TechCrunch Security
Popular AI gateway startup LiteLLM ditches controversial startup Delve | TechCrunch
LiteLLM had obtained two security compliance certifications via Delve and fell victim to some horrific credential-stealing malware last week.
original Mar 26 TechCrunch Security
Silicon Valley's two biggest dramas have intersected: LiteLLM and Delve | TechCrunch
LiteLLM offers an AI open source project used by millions that was infected by credential harvesting malware.
original Mar 26 TechCrunch Security
Delve did the security compliance on LiteLLM, an AI project hit by malware | TechCrunch
original Part of the PlainSec briefing for 2026-03-27
Every edition of this story: Supply-Chain Malware in LiteLLM Harvests Cloud Credentials
AI Security · Supply Chain
Supply-Chain Malware in LiteLLM Harvests Cloud Credentials A malicious PyPI dependency in the open-source LiteLLM project installed credential-harvesting malware that collected environment variables, SSH keys and passwords. LiteLLM is widely adopted—Snyk reports up to 3.4 million downloads per day—so stolen credentials could expose cloud keys, API tokens and downstream packages. Investigators traced the publishes to a compromised maintainer account used in LiteLLM's pipeline and flagged a possible link to an earlier Trivy compromise.
1 source · Mar 31
Timeline Sources Mar 31 TechCrunch Security
Popular AI gateway startup LiteLLM ditches controversial startup Delve | TechCrunch
LiteLLM had obtained two security compliance certifications via Delve and fell victim to some horrific credential-stealing malware last week.
original Mar 26 TechCrunch Security
Silicon Valley's two biggest dramas have intersected: LiteLLM and Delve | TechCrunch
LiteLLM offers an AI open source project used by millions that was infected by credential harvesting malware.
original Mar 26 TechCrunch Security
Delve did the security compliance on LiteLLM, an AI project hit by malware | TechCrunch
original Part of the PlainSec briefing for 2026-03-27
Every edition of this story: Supply-Chain Malware in LiteLLM Harvests Cloud Credentials