litellmPyPI
- latest 1.99.0
- licence MIT
- stars 57,928
- checked yesterday
- registry ↗
- repository ↗
Signals · last 1 check
State history 1
| When | Change |
|---|---|
| 2026-09-03 | first verdict: active |
Supply-chain history 1
-
account hijacked 2026-03 1.82.7, 1.82.8
Credentials stolen in the same campaign as the Trivy compromise published two releases that harvested environment variables, SSH, cloud and Kubernetes credentials on import and installed persistence.
PyPI quarantined the project; the maintainers told users to treat it as full credential exposure.
Source: Datadog Security Labs analysis, 24 March 2026. History, not a warning about today — the verdict above is about maintenance now.
Badge
Drop this in your README. It re-renders itself as the verdict changes.
[](https://isitdeadyet.dev/pypi/litellm)
Watch it
Get told when litellm changes state, changes licence, or is deprecated — instead of finding out during an incident.
Free for up to 25 packages. Signing in is a link sent to your email — there is no password to choose.