litellm: Credential Stealer Hidden in PyPI Wheel
A critical supply chain compromise in litellm==1.82.8 on PyPI was identified on March 24, 2026. The malicious PyPI wheel contains a credential stealer hidden in a litellm_init.pth file that executes during package initialization.
- Disclosed
- Last updated
- Blast radius
- Python applications using litellm==1.82.8, affecting any system executing the package initialization
- Ecosystems
- Attack vectors
- Threat actor
- Affected entities
- litellm · 1.82.8
On March 24, 2026, a critical supply chain compromise was discovered in the litellm package hosted on PyPI. The compromised version, litellm==1.82.8, contained a malicious litellm_init.pth file embedded in the distributed wheel package.
The .pth file mechanism is a standard Python feature that allows arbitrary code execution during interpreter initialization. In this case, the malicious file was designed to steal credentials from affected systems when the package was imported or used.
Any Python application or environment that installed and executed litellm==1.82.8 could have been compromised. Credentials accessible to the running Python process would be at risk of exfiltration.
Indicators of compromise
- Packages
- litellm==1.82.8
Remediation
- Immediately uninstall litellm==1.82.8 from all affected systems
- Upgrade to a patched version of litellm released after March 24, 2026
- Audit and rotate any credentials that may have been exposed on systems that ran the compromised version
- Review application logs and credential access logs for suspicious activity during the window the vulnerable package was installed
- Implement package pinning and verification in dependency management to prevent installation of compromised versions
Sources
- litellm: Credential Stealer Hidden in PyPI Wheel · StepSecurity
- LiteLLM and Telnyx compromised on PyPI: Tracing the TeamPCP supply chain campaign · Datadog Security Labs
Cite this entry
"litellm: Credential Stealer Hidden in PyPI Wheel." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed March 24, 2026; last updated June 7, 2026. https://supplychainattack.org/incident/litellm-credential-stealer-hidden-in-pypi-wheel-ythjti
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in afrit-name (PyPI)
Malicious code was discovered in the afrit-name package on PyPI. The incident was identified and documented by the OpenSSF malicious packages project.
PyPICompromised package - resolvedcritical
Malicious code in adv2099m7 (PyPI)
Malicious code was discovered in the adv2099m7 package on PyPI. The package was identified and cataloged by the OpenSSF malicious packages project.
PyPICompromised package - resolvedcritical
Malicious code in xolonavrylpbeb (PyPI)
Malicious code was discovered in the xolonavrylpbeb package on PyPI. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2025-41797.
PyPICompromised package - resolvedcritical
Malicious code in adrandom (PyPI)
The adrandom package on PyPI contained malicious code that executed spyware and information-stealing malware. It was part of a campaign by the EsqueleSquad group that published nearly 6,000 malicious packages across PyPI and NPM.
EsquelesquadPyPICompromised package