header-langage
简体中文
繁體中文
English
Tiếng Việt
한국어
日本語
ภาษาไทย
Türkçe
Scan to Download the APP

SlowMist CISO: LiteLLM Targeted in PyPI Supply Chain Attack, Sensitive Information such as Cryptocurrency Wallets and Cloud Credentials at Risk of Leakage

BlockBeats News, March 25, according to SlowMist Chief Information Security Officer 23pds, the Python AI gateway library LiteLLM, which has a monthly download volume of up to 97 million times, has experienced a PyPI supply chain attack. Attackers can steal sensitive information on users' devices through the `pip install litellm` command. The stolen sensitive data includes: SSH keys, cloud service credentials (AWS / GCP / Azure), Kubernetes configuration files, Git credentials, API keys in environment variables, shell history, cryptocurrency wallet information, and database passwords.

举报 Correction/Report
Correction/Report
Submit
Add Library
Visible to myself only
Public
Save
Choose Library
Add Library
Cancel
Finish