SafeDep
Install GitHub App
SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Multiple low confidence YARA matches, but no strong evidence to classify as malware.

Verification Record

The package contains a malicious .pth file (litellm_init.pth, 34,628 bytes) that automatically executes a credential-stealing script every time the Python interpreter starts.

Details

Note: This report is updated by a verification record

The package is not a malware. Multiple YARA rules have matched, but they are all low confidence. The YARA rules exotic_tld and post_exotic_tld matched because the package interacts with api.together.xyz. The discord_bot rule matched because the package has some files related to Discord interactions. The rule hidden_short_path_temp matched because the package uses /tmp/.npm_mcp_cache as a cache directory. The rules base64_commands, suspected_data_stealer, hardcoded_host_port_over_10k, xor_terms, http_hardcoded_ip and hardcoded_ip_port have also matched, but these are not strong indicators of malware on their own.

litellm@1.82.8Malicious
Verified
Analysed at: 3/24/26, 10:53 AM
Source: https://files.pythonhosted.org/packages/fd/78/2167536f8859e655b28adf09ee7f4cd876745a933ba2be26853557775412/litellm-1.82.8-py3-none-any.whl
SHA256: d2a0d5f564628773b6af7b9c11f6b86531a875bd2d186d7081ab62748a800ebb
Confidence: High