← Blog

Delve and LiteLLM Wave: Compliance Scrutiny After Malware (Mar 2026)

Share on X

March 2026 reporting tied Delve to the LiteLLM supply-chain episode: the open-source gateway had obtained SOC 2 / ISO 27001 work through Delve before malicious PyPI releases escalated industry attention. Parallel stories covered anonymous allegations about compliance evidence quality and Delve’s public response.

This is primarily a governance and assurance story—not a single downloadable “breach database.” We record it for context next to LiteLLM PyPI 2026 and downstream victims such as Mercor.

Sources: TechCrunch, TechCrunch (LiteLLM / Vanta)