Unknown
osv
ยท
GHSA-5mg7-485q-xm76
Two LiteLLM versions published containing credential harvesting malware
Published Mar 25, 2026
After an API Token exposure from an exploited trivy dependency, two new releases of `litellm` were uploaded to PyPI containing automatically activated malware, harvesting sensitive credentials and files, and exfiltrating to a remote API.
Anyone who has installed and run the project should assume any credentials available to litellm environment may have been exposed, and revoke/rotate thema ccordingly.
Affected AI Products
litellm