https://seclists.org/oss-sec/2026/q1/378: litellm pypi packages compromised, infostealer added
Published Mar 24, 2026
·Updated
Affected Software
1 affected component
pypi/litellm=1.82.7, =1.82.8
Frequently Asked Questions
1
What is the severity of vulnerability reported for pypi/litellm?
The vulnerability exploits a compromise of the litellm package leading to the inclusion of an infostealer which poses a significant security risk.
2
How do I fix the vulnerability in pypi/litellm?
To fix the vulnerability in pypi/litellm, ensure that you update to the latest version of the package, or remove it if you do not need it.
3
How does the compromise of pypi/litellm affect my application?
The compromise of pypi/litellm can lead to unauthorized data exposure and malicious activities within your application, jeopardizing its security.
4
What evidence supports the compromise of pypi/litellm?
Reports indicate that the litellm package has been tainted with infostealer malware, suggesting a verified compromise.
5
Is the compromise of pypi/litellm part of a larger attack?
Yes, the breach appears to be part of a broader attack involving the compromise of other related packages as well.