We ripped out litellm in one afternoon
On Monday, litellm versions 1.82.7 and 1.82.8 hit PyPI with credential-stealing malware baked in. The attack payload collected SSH keys, .env files, cloud credentials, Kubernetes configs, and shell history, encrypted everything with RSA-4096, and sent it to a fake domain. Then it tried to plant persistent backdoors in your kube-system namespace and at ~/.config/sysmon/sysmon.py.
We had litellm in our API gateway. Version 1.82.4 – safe, but one careless pip install --upgrade away from compromise.