
In a dramatic twist that feels straight out of a tech-themed drama, an alarming malware incident has been uncovered in LiteLLM, a widely-used open-source AI project from Y Combinator. This tool, which offers developers streamlined access to numerous AI models, has seen a staggering download rate of up to 3.4 million times daily, as reported by Snyk, a security research firm tracking the event. With 40,000 stars on GitHub and countless forks, LiteLLM has quickly become a favorite among developers. The malware was identified by Callum McMahon, a research scientist at FutureSearch, a company specializing in AI agents for web research. The malicious code infiltrated LiteLLM via a “dependency,” a component of other open-source software it relies on, and proceeded to steal login credentials from users. This allowed the malware to access more packages and harvest additional credentials, creating a cascading effect of security breaches. McMahon's investigation was sparked when his computer shut down after downloading LiteLLM, leading to the discovery of the malware. In a twist of irony, a bug in the malware's design contributed to the failure of his machine. Both McMahon and renowned AI researcher Andrej Karpathy speculated that the poorly crafted code indicated it might have been hastily written. Meanwhile, the LiteLLM development team has been tirelessly working to resolve the situation. Fortunately, the malware was detected within hours of its entry into the system. However, the incident has raised eyebrows about the security certifications LiteLLM proudly displayed on its website. As of March 25, LiteLLM touted its compliance with SOC2 and ISO 27001, certifications obtained through Delve, a startup accused of misleading clients by allegedly fabricating compliance data and using auditors who merely rubber-stamp reports. Delve has strongly denied these accusations. It’s critical to note that while these certifications are designed to ensure strong security practices, they do not guarantee immunity from malware attacks. Despite SOC2's focus on software dependency policies, vulnerabilities can still be exploited. Engineer Gergely Orosz highlighted the situation on social media, expressing disbelief that LiteLLM had indeed been ‘Secured by Delve.’ As for LiteLLM, CEO Krrish Dholakia has refrained from commenting on the partnership with Delve while prioritizing the investigation alongside Mandiant. "Our current focus is to actively investigate the incident. We commit to sharing the technical insights gained with the developer community once our forensic review concludes," Dholakia stated to TechCrunch.
Kalshi, the prediction market platform, has taken significant legal steps against Netflix, sending a cease-and-desist le...
TechCrunch | Jul 25, 2026, 17:10
Have you noticed an unusual trend where people are wrapping their wallets in aluminum foil? This peculiar practice has e...
Business Today | Jul 25, 2026, 02:45
A power line failure near Washington, DC, recently showcased a significant challenge faced by the electrical grid due to...
TechCrunch | Jul 25, 2026, 13:50
Warner Bros. Discovery has initiated legal proceedings against Amazon, accusing the tech giant of unlawful interference ...
TechCrunch | Jul 25, 2026, 21:25
In recent discussions, a once-obscure topic in artificial intelligence has surged to the forefront of debates among tech...
CNBC | Jul 25, 2026, 12:15