Monday, August 3, 2026

Apps & Consumer

LiteLLM hit by malware as compliance partner faces scrutiny

LiteLLM, an open-source AI tool downloaded as often as 3.4 million times per day, was hit by malware, raising questions about security certifications provided by compliance startup Delve.

LiteLLM hit by malware as compliance partner faces scrutiny
Photo: LiteLLM

LiteLLM, an open-source project that provides developers with access to artificial intelligence models, has 40K stars on GitHub. The project was recently hit by what has been described as atrocious malware. The tool, which is downloaded as often as 3.4 million times per day according to security researcher Snyk, was the victim of an attack. The security incident was caught relatively quickly, likely within hours, after a researcher discovered the breach.

The malware slipped into the system through a dependency—meaning other open-source software that the project relied upon. Research scientist Callum McMahon of FutureSearch, a company offering AI agents for web research, discovered the breach after the malware caused his machine to shut down. The malware was described by researchers as vibe coded due to its sloppy design. Once active, it functioned by stealing user credentials to harvest further access across other open-source packages.

The security breach has drawn intense scrutiny to LiteLLM’s reliance on Delve, a compliance startup backed by Y Combinator (the Silicon Valley startup accelerator). Delve has been accused of misleading its customers about their true compliance conformity by allegedly generating fake data and using auditors that rubber-stamp reports. Delve has denied these allegations of misconduct. Despite the controversy, as of March 25, LiteLLM’s website displayed two major security compliance certifications—SOC2 and ISO 27001—provided by Delve. These certifications are intended to show that a company has security policies in place to limit incidents, though they do not automatically prevent malware. Commenting on the situation on social media, engineer Gergely Orosz expressed surprise that LiteLLM was indeed secured by Delve.

While LiteLLM’s developers work to address the fallout of being a victim of attack, company leadership has turned to external security experts. Krrish Dholakia, the CEO of LiteLLM, declined to comment on the startup’s use of Delve but addressed the ongoing security response. “Our current priority is the active investigation alongside Mandiant. We are committed to sharing the technical lessons learned with the developer community once our forensic review is complete,” Dholakia said. Mandiant is a cybersecurity firm assisting with the investigation.

Why it matters

The incident highlights the security risks associated with open-source software dependencies in widely used artificial intelligence tools. It also raises critical questions about the reliability of automated security compliance certifications when provided by startups facing allegations of misconduct.