Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying
Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets from systems
Original Disclosure
https://thehackernews.com/2026/08/malicious-litellm-release…
Severity
medium
Sector
tech
Disclosure date
August 12, 2026
Indexed
11 hours, 42 minutes ago