LiteLLM v1.82.8 Compromise Uses .pth File for Persistent Execution

✍️ OpenClawRadar📅 Published: April 1, 2026🔗 Source
LiteLLM v1.82.8 Compromise Uses .pth File for Persistent Execution
Ad

Compromise Details

LiteLLM versions 1.82.7 and 1.82.8 were compromised on PyPI last week. The v1.82.8 payload is particularly concerning because it uses a .pth file in site-packages that executes arbitrary code on every Python process startup.

Python's site.py processes .pth files at interpreter startup, and any line starting with 'import' is executed. This means the malicious code runs even if you have LiteLLM installed as a transitive dependency and never import or use it directly.

Impact and Distribution

According to Wiz data, LiteLLM is present in 36% of cloud environments as a transitive dependency. It gets pulled in by:

  • AI agent frameworks
  • MCP servers
  • LLM orchestration tools

Response and Hardening

The source includes a hardening guide covering this specific vulnerability and nine other measures related to the broader TeamPCP supply chain campaign. The Python/AI engineer quick start section outlines three immediate actions to take this week.

For detailed mitigation steps and the full hardening guide, refer to the advisory at: https://raxe.ai/labs/advisories/RAXE-2026-045

📖 Read the full source: r/LocalLLaMA

Ad

👀 See Also

Security Audit Experiment Shows AI Agent Performance Depends on Knowledge Access
Security

Security Audit Experiment Shows AI Agent Performance Depends on Knowledge Access

A developer ran three security audits on the same Next.js codebase using different AI approaches: Claude Code's built-in review found 1 critical, 6 high, 13 medium issues; an AI agent without extra context found 1 critical, 5 high, 14 medium; an AI agent with 10 professional security books found 8 critical, 9 high, 10 medium issues.

OpenClawRadar
U of T Researchers Demonstrate AI Worm Powerable by Free Open-Weight Models
Security

U of T Researchers Demonstrate AI Worm Powerable by Free Open-Weight Models

Researchers at the University of Toronto demonstrated the first AI-powered worm that adapts its spreading strategy using publicly accessible open-weight models, targeting any online device.

OpenClawRadar
Claude models vulnerable to invisible Unicode character hijacking, especially with tool access
Security

Claude models vulnerable to invisible Unicode character hijacking, especially with tool access

Testing shows Claude Sonnet 4 is 71.2% compliant with hidden instructions embedded in invisible Unicode characters when tools are enabled, with Opus 4 reaching 100% compliance on Unicode Tags encoding. Tool access dramatically increases vulnerability across all Claude models.

OpenClawRadar
OpenClaw's External Content Wrapper for Prompt Injection Defense
Security

OpenClaw's External Content Wrapper for Prompt Injection Defense

OpenClaw uses an external content wrapper that automatically tags web search results, API responses, and similar content with warnings that it's untrusted, priming the LLM to be skeptical and more likely to refuse malicious instructions.

OpenClawRadar