ended3월 24일· 9 sources

LiteLLM Python package compromised by supply-chain attack

LiteLLM Python 패키지, 공급망 공격으로 악성코드 삽입

Why it matters

The litellm==1.82.8 package on PyPI was compromised with a malicious .pth file that auto-executes a credential-stealing payload whenever the Python interpreter starts, without requiring an explicit import. The embedded script collects a wide range of sensitive data including SSH keys, cloud provider credentials (AWS/GCP/Azure), Kubernetes secrets, crypto wallets, and CI/CD tokens, then encrypts and exfiltrates them.

9
Sources
+0
24h
Growth
173d
Active
.pth filebackdoorcompromisecredential harvestingcredential stealercredential theftdependency auditgomodelkuberneteslitellmllm gatewaymcpopen source securitypip installpip-auditpypipython packagessh keyssupply chain attacksupply-chain attackteampcptrivy

Sources

Related Issues