PyPI: litellm

GHSA-5mg7-485q-xm76

Safety vulnerability ID: SFTY-20260325-42188

After an API Token exposure from an exploited trivy dependency, two new releases of `litellm` were uploaded to PyPI containing automatically activated malware, harvesting sensitive credentials and files, and exfiltrating to a remote API. Anyone who has installed and run the project should assume any credentials available to litellm environment may have been exposed, and revoke/rotate thema ccordingly.

Created at: Mar 25, 2026Updated at: Mar 25, 2026

Overview

Two LiteLLM versions published containing credential harvesting malware

Advisory

Two LiteLLM versions published containing credential harvesting malware

Affected Package

Affecting litellm package, versions
>= 1.82.7, <= 1.82.8

Also affects

---

How to Fix

We recommend updating litellm to the latest non-vulnerable version.

Mitigation and Workarounds

---

Vulnerable Functions

Functions linked to known vulnerabilities.

Vulnerable function data is available for Enterprise customers

Book a call with us to see Safety in action.

Safety

Verified by Safety

Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.

Learn more