![[Security]: CRITICAL: Malicious litellm_init.pth in litellm 1.82.8 — credential stealer · Issue #24512 · BerriAI/litellm](https://pub-90f0ac00d93c47daac3e1d2cdd28d496.r2.dev/articles/51d46f16909604153de11fd523630f79.webp)
github.com
March 24, 2026
3 min read
72/100
Summary
The litellm 1.82.8 package on PyPI contains a malicious litellm_init.pth file that executes a credential-stealing script upon starting the Python interpreter. Users are advised to avoid this version to prevent credential theft.
Key Takeaways
Community Sentiment
Positives
Concerns