Tag: environment variable theft
1 article

Malicious LiteLLM Releases Expose Over 2,100 Organizations to Credential Theft
Over 2,100 organizations are at risk of credential theft due to malicious LiteLLM releases that harvested sensitive data, including environment variables, SSH keys, and cloud credentials, and sent it to an attacker-controlled domain. These compromised packages were live on PyPI for about 40 minutes on March 24, leaving a trail of potential exposure.