CRITICAL PyPI Malware
Malicious code in litellm (PyPI)
MAL-2026-2144 · PYSEC-2026-2
Published · Modified
Dependency scanning
Check whether litellm is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Description
__
Source: google-open-source-security (6a89401cbf53902e8374fbf3b424a77bb5e5f8c437176232eab7c3237d10ecbe)
LiteLLM was compromised through trivy security scan in a GitHub workflow.
Attackers uploaded malicious versions of LiteLLM to PyPI. The malicious
code would exfiltrate sensitive secrets to an attcker controlled domain.
Source: ossf-package-analysis (c1d5a2e721c5f8b33b0530ddf98150cadf034a8cd16483e143fc2925b2cfa70c)
The OpenSSF Package Analysis project identified 'litellm' @ 1.82.8 (pypi) as malicious.
It is considered malicious because:
- The package executes one or more commands associated with malicious behavior.
References
- REPORT https://github.com/BerriAI/litellm/issues/24518
- REPORT https://github.com/BerriAI/litellm/issues/24512
- DISCUSSION https://news.ycombinator.com/item?id=47501729
- ARTICLE https://www.wiz.io/blog/threes-a-crowd-teampcp-trojanizes-litellm-in-continuation-of-campaign
- ARTICLE https://futuresearch.ai/blog/litellm-pypi-supply-chain-attack/
Ready to move
Start Securing
Free, no credit card | First findings in minutes