Malicious code in litellm (PyPI)
UnratedPublished Mar 24, 2026 · updated Mar 26, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| litellm PyPI | <= 1.82.8 | No fix yet |
Details and references
--- _-= Per source details. Do not edit below this line.=-_ ## Source: google-open-source-security (6a89401cbf53902e8374fbf3b424a77bb5e5f8c437176232eab7c3237d10ecbe) LiteLLM was compromised through trivy security scan in a GitHub workflow. Attackers uploaded malicious versions of LiteLLM to PyPI. The malicious code would exfiltrate sensitive secrets to an attcker controlled domain. ## Source: ossf-package-analysis (c1d5a2e721c5f8b33b0530ddf98150cadf034a8cd16483e143fc2925b2cfa70c) The OpenSSF Package Analysis project identified 'litellm' @ 1.82.8 (pypi) as malicious. It is considered malicious because: - The package executes one or more commands associated with malicious behavior.
- Severity from
- no source yet
- Also known as
- PYSEC-2026-2
More LiteLLM advisories
All LiteLLM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 24 | Two litellm versions published containing credential harvesting malware PYSEC-2026-2Unratedno fix yet | Unrated | No fix yet |
| Mar 25 | Two LiteLLM versions published containing credential harvesting malware GHSA-5mg7-485q-xm76Criticalno fix yet | Critical | No fix yet |
| Apr 3 | LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint CVE-2026-35029Highfixed in 1.83.0 | High | 1.83.0 |
| Apr 3 | LiteLLM: Authentication bypass via OIDC userinfo cache key collision CVE-2026-35030Criticalfixed in 1.83.0 | Critical | 1.83.0 |
| Apr 8 | LiteLLM: Password hash exposure and pass-the-hash authentication bypass GHSA-69x8-hrgq-fjj8Highfixed in 1.83.0 | High | 1.83.0 |
| Apr 24 | LiteLLM: Server-Side Template Injection in /prompts/test endpoint CVE-2026-42203Highfixed in 1.83.7 | High | 1.83.7 |