#LiteLLM
6 stories taggedLiteLLM.

Most of the 2,500 organisations hit in the LiteLLM attack were actually victims of a different breach entirely
A closer look at the data shows the Trivy scanner compromise, not the LiteLLM package, caused almost all the damage, and stolen credentials are already on sale.

Poisoned LiteLLM Packages on PyPI May Have Leaked Secrets From 2,100 Organisations
CloudSEK says a 434,000-file dataset stolen during a 40-minute window in March traces back to two malicious releases of the popular AI gateway library.

Criminals Poisoned a Python Package Downloaded 95 Million Times a Month. AI Developers Were the Target.
On 24 March 2026, attackers slipped malicious code into LiteLLM, a software tool used by AI developers worldwide. Three hours online was enough to reach tens of thousands of companies.

Cryptomining attack on an AI gateway reveals a much bigger cloud security problem
Hackers broke into an Amazon cloud server acting as a doorway to AI services, planted mining software, and probed for wider access. The real worry is how much power these AI gateways hold.

Three-Bug Chain Turns Any LiteLLM User Into Root on the AI Gateway
A default low-privilege account on the popular open-source LLM proxy can escalate to admin and execute code, exposing every provider key the gateway holds.

LiteLLM Command Injection Hits CISA KEV as Attackers Chain to RCE
CVE-2026-42271 lets any authenticated user run shell commands on the LiteLLM proxy. CISA says it's already being exploited.