logo

Delve did the security compliance on LiteLLM, an AI project hit by malware

ID: d4c802ca-ce19-5c7a-90b7-ba86b6f18d51

STIX ID: report--d4c802ca-ce19-5c7a-90b7-ba86b6f18d51

Feed Name: TechCrunch Security News

Threat Score
78/100

Date Published: 2026-03-26

Date Updated: 2026-04-23

Author: Julie Bort

...
...

The report describes a supply‑chain malware incident in the widely used LiteLLM open‑source project: a malicious dependency stole login credentials and propagated to other packages/accounts after execution. Researcher Callum McMahon discovered and documented the infection, prompting a rapid investigation and remediation by LiteLLM with Mandiant involvement; the incident also raised questions about the project's third‑party security certification.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.