#24518 [Security]: litellm PyPI package (v1.82.7 + v1.82.8) compromised — full timeline and status
## The Trivy supply-chain compromise has been contained 🎉 . All affected packages have been deleted and current releases are free of the compromised code/component. Please refer to our [Security Townhall](https://docs.litellm.ai/blog/security-townhall-updates) for a deeper understanding of the problem, and [CI/CD v2](https://docs.litellm.ai/blog/ci-cd-v2-improvements) for how we're improving moving forward.
[LITELLM TEAM UPDATES]
- Compromised packages have been deleted (v1.82.7, v1.82.8) - Compromise came from trivvy security scan dependency - All maintainer accounts have been rotated (new maintainer accounts: @krrish-berri-2 , @ishaan-berri) - Proxy Docker image users were **not impacted**, all dependencies are pinned on requirements.txt - No litellm releases will be out until we have scanned our chain and make sure it's safe
Next Steps - Review all berriai repo's for impact - Scan circle ci builds to understand blast radius, and mitigate it - We've engaged Google's [mandiant.security](https://cloud.google.com/security/mandiant) team, and are actively working on this with them
We are actively investigating this issue. Please reach out to us on support@berri.ai, if you ha…