litellm

PyPI Compromised

1

report

Attack type: Other

Reports

Other Versions: >= 1.82.7, <= 1.82.8 22d ago by isitcompromised.com

Two LiteLLM versions published containing credential harvesting malware After an API Token exposure from an exploited trivy dependency, two new releases of `litellm` were uploaded to PyPI containing automatically activated malware, harvesting sensitive credentials and files, and exfiltrating to a remote API. Anyone who has installed and run the project should assume any credentials available to litellm environment may have been exposed, and revoke/rotate thema ccordingly.

View evidence

Have more info?

Submit additional evidence or a new report for this package.

Submit a report