The Litellm 1.82.7 and 1.82.8 packages on PyPI were compromised with malicious code, affecting over 40,000 monthly downloads. Security scans uncovered a hidden backdoor that exfiltrates API keys, putting every LLM project at risk — 15% of all Hugging Face deployments now face potential breaches. Worse than #10, this supply chain attack on a top orchestration tool requires immediate rollback to version 1.82.6, which is 99.9% clean per the maintainer’s audit. With 2,400 GitHub stars, Litellm's users must act fast: reinstall from source or face a 100% likelihood of credential theft within 24 hours.

Comments on "Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised"
Create a free account or sign in to join the discussion.
Sign in to join the conversation