Back to articles
PyPI Supply Chain Attack Compromises LiteLLM, Enabling the Exfiltration of Sensitive Information

PyPI Supply Chain Attack Compromises LiteLLM, Enabling the Exfiltration of Sensitive Information

via InfoQSergio De Simone

Discovered by FutureSearch researcher Callum McMahon, a supply chain attack against LiteLLM on PyPI resulted in over 40 thousand downloads of a compromised version that installed a malicious payload capable of harvesting and exfiltrating sensitive information. LiteLLM is downloaded roughly 3 million times per day. By Sergio De Simone

Continue reading on InfoQ

Opens in a new tab

Read Full Article
10 views

Related Articles