Observed Signal · Mar 26, 2026 · Security Incident · Source: techcrunch · Impact: 3/5 · Sentiment: Negative
LiteLLM Malware Exposes Delve Compliance Claims
A severe supply‑chain malware infection was discovered in LiteLLM, a popular open‑source project that provides unified access to many AI models. Research scientist Callum McMahon of FutureSearch found the malware after his machine shut down following a LiteLLM download; the malicious code entered via a dependency, stole login credentials and propagated to other packages. Security firm Snyk reported LiteLLM downloads as high as 3.4 million per day and noted the project had ~40K GitHub stars. LiteLLM displayed SOC 2 and ISO 27001 certifications obtained through Delve, an AI‑powered compliance startup now accused elsewhere of misleading customers about conformity (Delve denies the allegations). LiteLLM says it is investigating with Mandiant and performing a forensic review; CEO Krrish Dholakia declined to comment on Delve’s role. The incident highlights risks in dependency management and limits of certification-based assurances.
A supply-chain malware incident in a widely used open-source LLM project and questions about a third-party compliance vendor (Delve) raise software supply-chain, vendor risk and trust issues for organizations — including those in AdTech — that integrate OSS AI tooling.
Track LiteLLM Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Malware was discovered in the open-source LiteLLM project and entered via a dependency.
- Callum McMahon (Research Scientist, FutureSearch) discovered, documented and disclosed the malware after his machine shut down.
- Snyk reported LiteLLM downloads as high as 3.4 million per day; LiteLLM had about 40,000 GitHub stars.
- LiteLLM listed SOC 2 and ISO 27001 certifications obtained through Delve; Delve denies accusations that it misled customers about compliance.
- LiteLLM said it is investigating the incident with Mandiant and conducting a forensic review.
Connected Companies & Entities
4 Entities mappedOntology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
LiteLLM Drops Delve, Re-certifies Security With Vanta
LiteLLM, the provider of a widely used AI gateway, announced it is ending its relationship with compliance startup Delve and will re-run its security certifications with competitor Vanta and an independent third‑party auditor. The move follows a recent incident in which LiteLLM’s open‑source offering was compromised by credential‑stealing malware. Previously, LiteLLM had obtained two compliance certifications through Delve. Delve has been accused by an anonymous whistleblower of fabricating data and using lax auditors; Delve’s founder denies the claims and offered free re‑tests. LiteLLM CTO Ishaan Jaffer posted on X that the company will seek fresh certification and independent verification after the security breach and surrounding controversy.
LiteLLM PyPI Backdoor Exposes Python LLM Gateway Risk
On March 24, 2026, threat actor group TeamPCP used stolen CI credentials (exfiltrated via a compromised Trivy GitHub Action) to publish two backdoored LiteLLM releases (1.82.7 and 1.82.8) to PyPI. The multi-stage malware harvested SSH keys, cloud (AWS/GCP/Azure) credentials, Kubernetes secrets, cryptocurrency wallets, and installed persistent backdoors; exfiltration used models.litellm.cloud. Version 1.82.8 employed a litellm_init.pth startup hook that ran on interpreter start, widening impact beyond explicit imports. Snyk, Wiz, FutureSearch and LiteLLM published technical analyses and mitigations. The incident highlights systemic Python supply-chain risks for LLM gateways (packages that hold provider API keys) and recommends immediate steps: check versions, scan for malicious .pth files, rotate credentials, pin dependencies and CI actions, and consider compiled or managed gateway alternatives.
Mercor Hit by LiteLLM Supply-Chain Cyberattack
Mercor, an AI recruiting startup, confirmed a security incident tied to a supply-chain compromise of the open-source LiteLLM project. The compromise has been linked to a hacking group called TeamPCP, and extortion group Lapsus$ has claimed it targeted Mercor and posted a sample of purportedly stolen data. Mercor said it is one of “thousands of companies” affected, has engaged third-party forensics, and is communicating with customers and contractors. LiteLLM’s maintainers removed malicious code from a package within hours; security firm Snyk reported the library is widely used and downloaded millions of times per day. Mercor — founded in 2023, a partner to OpenAI and Anthropic — was valued at $10 billion after a $350 million Series C led by Felicis Ventures in October 2025. Investigations into the scope and any data exposure remain ongoing.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
