Your AI Stack Just Handed Over Your Root Keys: Inside the litellm PyPI Breach
ID: e37e209a-14e3-5cce-8bfe-794ffd964b5d
STIX ID: report--e37e209a-14e3-5cce-8bfe-794ffd964b5d
Feed Name: TrendAI Security Blog
A supply‑chain compromise of the litellm PyPI package (v1.82.7 and v1.82.8) delivered a malicious payload that auto‑executes on interpreter startup, steals cloud provider credentials (AWS/GCP/Azure), SSH keys, and Kubernetes service account tokens, attempts container escapes and persistence on host nodes, and exfiltrates data to attacker-controlled domains (e.g., checkmarx.zone); the report provides IoCs (files, daemon names, outbound domains), widespread impact metrics, and immediate remediation guidance including package removal and credential rotation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
