AI · 185 giorni fa
Un dependency su PyPI del progetto open-source LiteLLM conteneva malware per il credential harvesting, secondo ricercatori e vendor. LiteLLM instrada richieste fra AI models e può accedere a environment variables, SSH keys e API tokens. Snyk riporta fino a 3.4 milioni di download al giorno, ampliando il rischio lungo la supply chain.
1 fonte che coprono questa storia
Popular AI gateway startup LiteLLM ditches controversial startup Delve | TechCrunch
LiteLLM had obtained two security compliance certifications via Delve and fell victim to some horrific credential-stealing malware last week.
Silicon Valley's two biggest dramas have intersected: LiteLLM and Delve | TechCrunch
LiteLLM offers an AI open source project used by millions that was infected by credential harvesting malware.
Delve did the security compliance on LiteLLM, an AI project hit by malware | TechCrunch
LiteLLM offers an AI open source project used by millions that was infected by credential harvesting malware.
Part of the PlainSec briefing for 2026-03-27