arrow_backBack to Radio
News

SlowMist: LiteLLM experienced a PyPI supply chain attack, with malicious files planted capable of stealing sensitive information such as crypto wallets.

en
On March 25, SlowMist Chief Information Security Officer 23pds posted on X: "LiteLLM, with up to 97 million monthly downloads, has suffered a PyPI supply chain attack: sensitive information including SSH keys, cloud credentials (AWS/GCP/Azure), Kubernetes configurations, Git credentials, environment variables (API keys), shell history, encrypted wallets, and database passwords can be stolen by running `pip install litellm`."
Share