LiteLLM Library Hit by PyPI Supply Chain Attack: 97M Monthly Downloads at Risk

LiteLLM Library Hit by PyPI Supply Chain Attack: 97M Monthly Downloads at Risk

N
News Editor 01
2026-07-10 23:52:13
SlowMist disclosed a PyPI supply chain attack on LiteLLM (97M monthly downloads). Attackers can steal SSH keys, cloud credentials, crypto wallet info, etc. Users urged to verify installations.
supply chain attackPyPIPython librarycryptocurrency walletdata breach

On July 10, 2026, SlowMist, a blockchain security firm, revealed that the popular Python AI gateway library LiteLLM has been compromised in a PyPI supply chain attack. With a staggering 97 million monthly downloads, LiteLLM is widely used in AI development. The attack exploits the pip install litellm command to execute malicious code, enabling attackers to exfiltrate sensitive data from victims' devices.

Scope of Stolen Data

According to 23pds, SlowMist's CISO, the compromised package can harvest SSH keys, cloud service credentials (AWS, GCP, Azure), Kubernetes configuration files, Git credentials, API keys from environment variables, shell history, cryptocurrency wallet information, and database passwords. This data could lead to cloud infrastructure takeover, digital asset theft, and source code repository breaches.

Security Recommendations and Context

23pds strongly advises all LiteLLM users to immediately verify the integrity of their installations by checking package hashes and ensuring they downloaded from official sources. This attack is part of a rising trend of cross-registry supply chain attacks targeting crypto and AI developers. Previously, SlowMist identified malicious packages on npm, PyPI, and Crates.io (e.g., TrapDoor Stealer), as well as vulnerabilities in OpenAI Codex. Cryptocurrency developers are especially vulnerable as stolen wallet credentials can lead to direct financial loss.

Given the wide adoption of LiteLLM, the impact could be severe. Security experts call for enhanced package review processes on PyPI and recommend developers use pip install --no-deps or verify checksums in requirements.txt. Regularly rotating credentials and using hardware wallets for crypto assets are also effective countermeasures.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.