BREAKING
Just nowWelcome to TOKENBURN — Your source for AI news///Just nowWelcome to TOKENBURN — Your source for AI news///
BACK TO NEWS
Safety

Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised

Malicious .pth files in LiteLLM 1.82.7 and 1.82.8 (PyPI) automatically steal SSH keys, API tokens, and cloud credentials from any dependent Python project.

Wednesday, March 25, 2026 12:00 PM UTC2 MIN READSOURCE: Hacker NewsBY sys://pipeline

LiteLLM versions 1.82.7 and 1.82.8 on PyPI contain a malicious `.pth` file that executes a credential-stealing payload automatically on every Python interpreter start — no import required. The payload collects SSH keys, environment variables (capturing API keys and tokens), git credentials, and cloud provider configs, then exfiltrates them. Any developer or AI pipeline with litellm in its dependency tree should audit immediately and rotate credentials.

Tags
safety
/// RELATED