litellm
MAL-2026-2144
PyPImalware3/24/2026
Description
Malicious code in litellm (PyPI)
Indicators of Compromise
SHA256 Hashes (2)
6a89401cbf53902e8374fbf3b424a77bb5e5f8c437176232eab7c3237d10ecbe
c1d5a2e721c5f8b33b0530ddf98150cadf034a8cd16483e143fc2925b2cfa70c
Domains (1)
litellm.cloud
References (5)
https://github.com/BerriAI/litellm/issues/24518OSVhttps://github.com/BerriAI/litellm/issues/24512OSVhttps://news.ycombinator.com/item?id=47501729OSVhttps://www.wiz.io/blog/threes-a-crowd-teampcp-trojanizes-litellm-in-continuation-of-campaignOSVhttps://futuresearch.ai/blog/litellm-pypi-supply-chain-attack/OSV
Details
EcosystemPyPI
Attack Typemalware
Published3/24/2026
Aliases
PYSEC-2026-2
Quick Actions