The LiteLLM Package Was Poisoned for 40 Minutes. The Keys Lasted for Months
| 21 min read
For Developers New analysis of the March LiteLLM supply-chain attack found credentials from thousands of organizations, with some still working months later. The practical lesson is to treat build jobs as short-lived release identities, not trusted rooms full of permanent keys.