AI · 168 days ago
A malicious PyPI dependency in the open-source LiteLLM project installed credential-harvesting malware that collected environment variables, SSH keys and passwords. LiteLLM is widely adopted—Snyk reports up to 3.4 million downloads per day—so stolen credentials could expose cloud keys, API tokens and downstream packages. Investigators traced the publishes to a compromised maintainer account used in LiteLLM's pipeline and flagged a possible link to an earlier Trivy compromise.
1 source covering this story
Popular AI gateway startup LiteLLM ditches controversial startup Delve | TechCrunch
LiteLLM had obtained two security compliance certifications via Delve and fell victim to some horrific credential-stealing malware last week.
Silicon Valley's two biggest dramas have intersected: LiteLLM and Delve | TechCrunch
LiteLLM offers an AI open source project used by millions that was infected by credential harvesting malware.
Delve did the security compliance on LiteLLM, an AI project hit by malware | TechCrunch
LiteLLM offers an AI open source project used by millions that was infected by credential harvesting malware.
Part of the PlainSec briefing for 2026-03-27