By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Malicious LiteLLM Versions Exposed 2,100+ Organizations

Two malicious versions of the open-source LiteLLM Python package were discovered on the Python Package Index (PyPI) in March, remaining undetected for approximately 40 minutes before being removed. These compromised packages contained malicious code designed to steal sensitive credentials, including cloud API keys, SSH keys, Kubernetes tokens, and database passwords. Threat intelligence firm CloudSEK obtained a dataset comprising approximately 434,000 files that were captured by the attackers. Analysis of this dataset suggests that the attack may have impacted over 2,100 organizations. The compromised versions of LiteLLM were identified as versions 1.1.11 and 1.1.12. The attackers leveraged a technique known as "typosquatting," releasing malicious packages with names similar to legitimate ones to trick developers into installing them. LiteLLM is a popular library that provides a unified interface to various large language models (LLMs) from providers such as OpenAI, Anthropic, and Google, simplifying the process for developers to switch between different AI models. The discovery of these malicious packages highlights ongoing security risks within the open-source software supply chain. Developers and organizations are urged to exercise caution when installing third-party libraries and to implement robust security practices, such as dependency scanning and code review, to mitigate the risk of supply chain attacks. The Trivy vulnerability, a separate security issue, was also mentioned in relation to this incident, though the exact connection and impact on the Trivy vulnerability itself were not fully detailed in the provided text. The primary concern remains the credential-stealing capabilities embedded within the malicious LiteLLM releases. CloudSEK's analysis indicates that the attackers were actively harvesting secrets from compromised systems. The scale of the potential exposure, affecting over 2,100 organizations, underscores the widespread reliance on open-source tools and the critical need for enhanced security measures in software development workflows. The incident serves as a stark reminder of the persistent threats posed by malicious actors targeting popular open-source repositories to distribute malware and compromise sensitive data. Further investigation into the full extent of the compromise and the identity of the attackers is likely ongoing.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.