⚠️ Security Notice: litellm 1.82.x Supply Chain Attack #726
srbhr
announced in
Announcements
Replies: 2 comments 4 replies
|
We're using: From: apps/backend/requirements.txt apps/backend/pyproject.toml |
3 replies
|
What |
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
If you are running Resume Matcher and recently upgraded litellm to version 1.82.x, please read this immediately.
A malicious file was discovered in the
litellm==1.82.8(some folks on hacker news are saying 1.82.7 or older have been compromised too) PyPI package that automatically steals and exfiltrates credentials (API keys, SSH keys, environment variables, cloud credentials) every time Python starts no import required.References
All reactions