Skip to content
LiteLLMGHSA-5mg7-485q-xm76

Two LiteLLM versions published containing credential harvesting malware

CriticalPublished Mar 25, 2026 · updated Mar 27, 2026

After an API Token exposure from an exploited trivy dependency, two new releases of `litellm` were uploaded to PyPI containing automatically activated malware, harvesting sensitive credentials and files, and exfiltrating to a remote API. Anyone who has installed and run the project should assume any credentials available to litellm environment may have been exposed, and revoke/rotate thema ccordingly.

GitHub advisory

Affected versions

PackageAffectedFixed in
litellm
PyPI
>= 1.82.7, <= 1.82.8No fix yet
Details and references

More LiteLLM advisories

All LiteLLM

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.