LiteLLM Package Compromised

Alert: [Security]: litellm PyPI package compromised — full timeline and status · Issue #24518 · BerriAI/litellm · GitHub

Original Analysis: [Security]: CRITICAL: Malicious litellm_init.pth in litellm 1.82.8 — credential stealer · Issue #24512 · BerriAI/litellm · GitHub

Evil code like:

import os, subprocess, sys; subprocess.Popen([sys.executable, "-c", "import base64; exec(base64.b64decode('...'))"])

litellm[.]cloud connected to 46.151.182[.]203 - the whole /24 is baaaaaad. ASN 205759.

There’s some confusion about which versions were affected. This issue seems to be up-to-date.

PyPi has pulled the entire package.

And a valuable putative timeline, showing Trivy as the access vector: [Security]: litellm PyPI package (v1.82.7 + v1.82.8) compromised — full timeline and status · Issue #24518 · BerriAI/litellm · GitHub

Can’t post the evidence in the clear, but TeamPCP is directly and purposely targeting scanning and security solutions.

This follows, since they claimed responsibility for the Trivy compromise:

Aaaand KICS:

Interesting direct quotes from Mandiant IR here: