Skip to content
LiteLLMMAL-2026-2144

Malicious code in litellm (PyPI)

UnratedPublished Mar 24, 2026 · updated Mar 26, 2026

Source advisory

Affected versions

PackageAffectedFixed in
litellm
PyPI
<= 1.82.8No fix yet
Details and references

--- _-= Per source details. Do not edit below this line.=-_ ## Source: google-open-source-security (6a89401cbf53902e8374fbf3b424a77bb5e5f8c437176232eab7c3237d10ecbe) LiteLLM was compromised through trivy security scan in a GitHub workflow. Attackers uploaded malicious versions of LiteLLM to PyPI. The malicious code would exfiltrate sensitive secrets to an attcker controlled domain. ## Source: ossf-package-analysis (c1d5a2e721c5f8b33b0530ddf98150cadf034a8cd16483e143fc2925b2cfa70c) The OpenSSF Package Analysis project identified 'litellm' @ 1.82.8 (pypi) as malicious. It is considered malicious because: - The package executes one or more commands associated with malicious behavior.

Severity from
no source yet
Also known as
PYSEC-2026-2

More LiteLLM advisories

All LiteLLM
DateAdvisory
Mar 24Two litellm versions published containing credential harvesting malware
PYSEC-2026-2Unratedno fix yet
Mar 25Two LiteLLM versions published containing credential harvesting malware
GHSA-5mg7-485q-xm76Criticalno fix yet
Apr 3LiteLLM: Privilege escalation via unrestricted proxy configuration endpoint
CVE-2026-35029Highfixed in 1.83.0
Apr 3LiteLLM: Authentication bypass via OIDC userinfo cache key collision
CVE-2026-35030Criticalfixed in 1.83.0
Apr 8LiteLLM: Password hash exposure and pass-the-hash authentication bypass
GHSA-69x8-hrgq-fjj8Highfixed in 1.83.0
Apr 24LiteLLM: Server-Side Template Injection in /prompts/test endpoint
CVE-2026-42203Highfixed in 1.83.7

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.