Litellm has been compromised

Reddit r/LocalLLaMA / 2026/3/25

📰 ニュースDeveloper Stack & InfrastructureSignals & Early TrendsTools & Practical Usage

要点

  • Litellm on PyPI has reportedly been compromised with a credential-stealing payload, indicating a supply-chain security incident affecting Python package distribution.
  • Because Litellm is widely used as a core dependency across open-source stacks (including references such as Ollama), downstream users may have been exposed via automated updates or recent downloads.
  • The reported mitigation is to downgrade to version 1.82.6 or lower if you updated or installed Litellm after March 24.
  • The incident highlights the risk of credential theft within AI/LLM tooling dependencies and the need for immediate dependency version checks and rollback where applicable.

Litellm on PyPI has been compromised with a credential stealing payload. Litellm is a core dependency across oss stacks (ollama even). If you have auto updates to anything that uses litellm or downloaded litellm after march 24, downgrade to 1.82.6 or lower.

submitted by /u/Blahblahblakha
[link] [comments]