{
    "byline": "isfinneopened on Mar 24, 2026Issue body actions",
    "charset": "UTF-8",
    "dir": null,
    "excerpt": "The litellm==1.82.8 wheel package on PyPI contains a malicious .pth file (litellm_init.pth, 34,628 bytes) that automatically executes a credential-stealing script every time the Python interpreter starts \u2014 no import litellm required.",
    "lang": null,
    "length": 4792,
    "publishedTime": null,
    "siteName": null,
    "title": ""
}