Popular AI proxy LiteLLM got hacked with malware that spreads through Kubernetes clusters

THE DECODER / 3/25/2026

📰 NewsDeveloper Stack & InfrastructureSignals & Early Trends

Key Points

  • LiteLLM, an open-source AI API proxy, was reportedly compromised with malware designed to steal credentials and propagate across cloud environments.
  • The infection leverages Kubernetes cluster access to spread, highlighting how container orchestration can amplify attacker reach.
  • NVIDIA AI Director Jim Fan characterizes the incident as indicative of a new class of attacks aimed at AI agents and the surrounding infrastructure.
  • The event underscores the need for tighter security controls around AI tooling, including credential hygiene, cluster segmentation, and malware detection/response for AI-related services.

LiteLLM, a popular open-source proxy for AI APIs, has been compromised with malware that steals credentials and spreads across cloud systems. NVIDIA AI Director Jim Fan warns this represents a new class of attacks targeting AI agents.

The article Popular AI proxy LiteLLM got hacked with malware that spreads through Kubernetes clusters appeared first on The Decoder.