LiteLLM malware steals data; Delve certs in doubt

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- LiteLLM had 40K GitHub stars and was downloaded up to 3.4 million times per day, according to security researcher Snyk, before the malware incident.
- Callum McMahon of FutureSearch discovered the malware after his machine shut down downloading LiteLLM; he documented and disclosed it, noting it entered via a dependency and stole login credentials.
- Andrej Karpathy remarked that the sloppy code indicated the malware was likely "vibe coded."
- LiteLLM developers are working with Mandiant on an active investigation and plan to share technical lessons after a forensic review.
- Delve, the compliance startup that provided LiteLLM’s SOC2 and ISO 27001 certifications, has been accused of generating fake data and rubber‑stamping reports, though it denies the claims.
- Gergely Orosz highlighted on X that the "Secured by Delve" claim was ironic given the breach.
Why it matters: Developers relying on LiteLLM now face credential theft and forced remediation, while the breach calls into question the value of LiteLLM’s SOC2/ISO 27001 seals obtained through Delve—an alleged audit‑faking firm—potentially eroding confidence in compliance certifications for AI tooling and prompting tighter scrutiny of supply‑chain dependencies.



