ended3월 24일· 9 sources
LiteLLM Python package compromised by supply-chain attack
LiteLLM Python 패키지, 공급망 공격으로 악성코드 삽입
Why it matters
The litellm==1.82.8 package on PyPI was compromised with a malicious .pth file that auto-executes a credential-stealing payload whenever the Python interpreter starts, without requiring an explicit import. The embedded script collects a wide range of sensitive data including SSH keys, cloud provider credentials (AWS/GCP/Azure), Kubernetes secrets, crypto wallets, and CI/CD tokens, then encrypts and exfiltrates them.
9
Sources
+0
24h
—
Growth
173d
Active
.pth filebackdoorcompromisecredential harvestingcredential stealercredential theftdependency auditgomodelkuberneteslitellmllm gatewaymcpopen source securitypip installpip-auditpypipython packagessh keyssupply chain attacksupply-chain attackteampcptrivy
Sources
hackernews
LiteLLM Python package compromised by supply-chain attack3월 24일
devtoYour `pip install` Just Stole Your SSH Keys: The LiteLLM Supply Chain Attack Explained3월 24일
lobstersLiteLLM Compromised by Credential Stealer3월 24일
devtoLiteLLM PyPI Compromise Is Just the Beginning — How to Audit Your Python Dependencies Right Now3월 25일
devtoLiteLLM Supply Chain Attack - Deep Dive3월 24일
devtoLiteLLM Was Compromised. That's Why I'm Building GoModel3월 24일
reddit_progMalicious litellm 1.82.8: Credential Theft and Persistent Backdoor3월 24일
reddit_progLitellm 1.82.7 and 1.82.8 on PyPI are compromised, do not update!3월 24일
geeknewsLiteLLM이 공급망 공격으로 해킹당했습니다.3월 24일