Litellm 1.82.7 and 1.82.8 on PyPI are compromised, do not update! (opens in new tab)
litellm version 1.82.8 on PyPI contains a malicious .pth file that harvests SSH keys, cloud credentials, and secrets on every Python startup, then attempts lateral movement across Kubernetes clusters.
Read the original article