Python Supply-Chain Compromise
ID: fcf500c8-cb0f-5b0d-a028-f93f2649c7cc
STIX ID: report--fcf500c8-cb0f-5b0d-a028-f93f2649c7cc
Feed Name: Schneier on Security
Threat Score
A malicious supply-chain compromise was identified in the PyPI package litellm v1.82.8: the published wheel includes a malicious .pth file (litellm_init.pth, 34,628 bytes) that the Python interpreter executes automatically on startup, enabling code execution without importing the module. The report calls for stronger supply-chain protections (SBOMs, SLSA, SigStore) to help secure critical libraries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
