LiteLLMGHSA-5mg7-485q-xm76
Two LiteLLM versions published containing credential harvesting malware
CriticalPublished Mar 25, 2026 · updated Mar 27, 2026
After an API Token exposure from an exploited trivy dependency, two new releases of `litellm` were uploaded to PyPI containing automatically activated malware, harvesting sensitive credentials and files, and exfiltrating to a remote API. Anyone who has installed and run the project should assume any credentials available to litellm environment may have been exposed, and revoke/rotate thema ccordingly.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| litellm PyPI | >= 1.82.7, <= 1.82.8 | No fix yet |
Details and references
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-506
- github.com/BerriAI/litellm/issues/24518
- docs.litellm.ai/blog/security-update-march-2026
- futuresearch.ai/blog/litellm-pypi-supply-chain-attack
- github.com/BerriAI/litellm
- github.com/pypa/advisory-database/tree/main/vulns/litellm/PYSEC-2026-2.yaml
- inspector.pypi.io/project/litellm/1.82.7/packages/79/5f/b6998d42c6ccd32d36e12661f2734602e72a576d52a51f4245aef0b20b4d/litellm-1.82.7-py3-none-any.whl/litellm/proxy/proxy_server.py#line.130
- inspector.pypi.io/project/litellm/1.82.8/packages/f6/2c/731b614e6cee0bca1e010a36fd381fba69ee836fe3cb6753ba23ef2b9601/litellm-1.82.8.tar.gz/litellm-1.82.8/litellm_init.pth#line.1
- www.wiz.io/blog/teampcp-attack-kics-github-action
More LiteLLM advisories
All LiteLLM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Apr 24 | LiteLLM: Server-Side Template Injection in /prompts/test endpoint | High | 1.83.7 |
| Apr 8 | LiteLLM: Password hash exposure and pass-the-hash authentication bypass | High | 1.83.0 |
| Apr 3 | LiteLLM: Authentication bypass via OIDC userinfo cache key collision | Critical | 1.83.0 |
| Apr 3 | LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint | High | 1.83.0 |
| Mar 24 | Two litellm versions published containing credential harvesting malware | Unrated | No fix yet |
| Mar 24 | Malicious code in litellm (PyPI) | Unrated | No fix yet |