LiteLLM supply chain attack exposes millions to credential theft

Researchers at Endor Labs, have discovered a supply chain attack on the popular Python package LiteLLM on PyPI, with malicious code injected into versions 1.82.7 and 1.82.8, which have been withdrawn.   The package is used in AI environments and developer tools, with an estimated 95 million downloads per month.  The malicious packages included credential-stealing malware, including a .pth file that can […]

This article has been indexed from Information Security Buzz

Read the original article: