InfoQ AI/ML

PyPI Supply Chain Attack Compromises LiteLLM, Enabling the Exfiltration of Sensitive Information

Back to overview

A PyPI supply chain attack compromised LiteLLM, a popular AI library downloaded 3 million times daily. Over 40,000 users downloaded a malicious version that exfiltrated sensitive data. Researcher Callum McMahon discovered the attack, which injected a harmful payload capable of stealing information. This highlights critical supply chain vulnerabilities in AI development ecosystems and the need for enhanced security measures.