LiteLLM malware breach hits 3.4M-daily AI toolkit

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- LiteLLM, a Y Combinator open source project downloaded roughly 3.4 million times per day and holding 40,000 GitHub stars, was found to contain malware that stole login credentials from infected machines and then used those credentials to compromise additional open source packages and accounts.
- Callum McMahon, a research scientist at FutureSearch, discovered the malware after his machine crashed upon downloading LiteLLM; he and AI researcher Andrej Karpathy both concluded the sloppy, bug-ridden code was 'vibe coded.'
- The malware entered through a software dependency rather than LiteLLM's own code, harvesting credentials from everything it touched and chaining onward into more open source packages, and was reportedly caught within hours.
- LiteLLM as of March 25 still prominently displays SOC2 and ISO 27001 compliance certifications on its website obtained through Delve, a Y Combinator AI-powered compliance startup that has been accused of generating fake data and using auditors who rubber-stamp reports.
- LiteLLM CEO Krrish Dholakia declined to comment on the use of Delve and told TechCrunch the company's current priority is an active investigation alongside Mandiant, with technical lessons to be shared with the developer community once the forensic review is complete.
Why it matters: A single compromised dependency in a package pulled 3.4 million times daily shows how the open source supply chain can turn one infection into credential theft across thousands of developer machines in hours. The overlap with Delve-issued certifications turns the incident into a live test of whether AI-driven compliance audits are catching the risks they are marketed to prevent.



