🚨 Security Alert – Immediate Action Required"
🚨 Security Alert – Immediate Action Required"
""
"Earlier today, two malicious versions of LiteLLM were briefly published on PyPI between 10:39 UTC and 14:35 UTC before being quarantined."
""
"⚠️ Who is impacted?"
"If you installed any packages during this window that depend on LiteLLM, including running pip install dspy, you should assume potential compromise."
""
"✅ Who is safe?"
"If you did not perform any installations between 10:39 UTC and 14:35 UTC, no action is required. The affected versions have been removed and the package has been restored."
""
"🚨 Critical risk versions:"
" • LiteLLM v1.82.7"
" • LiteLLM v1.82.8"
""
"Check your version using:"
"pip show litellm | grep Version"
""
"These versions contained a malicious .pth file that harvested environment variables and credentials and sent them to an attacker-controlled domain."
""
"🛑 Immediate actions to take:"
" • Rotate all tokens, API keys, and credentials immediately"
" • Inspect your system for persistence artifacts:"
" • ~/.config/sysmon/sysmon.py"
" • ~/.config/systemd/user/sysmon.service"
" • Treat the affected environment as compromised until verified clean"
""
"Stay vigilant and act quickly if you fall within the impacted window.