Junglewise Threat Intelligence

Aurelio Labs semantic-router supply chain compromise via litellm dependency

Severity: critical · CVSS 10 · Published 2026-06-26

Vendors: PyPI.

Executive brief

Aurelio Labs semantic-router, a library for AI decision-making, was found to have a dependency configuration that allowed the installation of a compromised version of the litellm package. If a user installed semantic-router during a specific window in 2026, a malicious version of the dependency could have been automatically downloaded. This malicious code is designed to steal sensitive information, including cloud provider credentials (AWS/GCP/Azure), SSH keys, Kubernetes configurations, and database secrets, potentially leading to a full compromise of the user's environment.

Technical details

semantic-router versions 0.1.8 through 0.1.14 used an unbounded dependency pin (litellm>=1.61.3), which allowed the installation of a compromised 'litellm' wheel (version 1.82.8) from PyPI. The malicious wheel contains a 'litellm_init.pth' file that executes arbitrary Python code upon interpreter startup without requiring an explicit import. The payload exfiltrates environment variables, cloud credentials, SSH keys, and CI/CD secrets to a remote server (https://models.litellm.cloud/) using AES-256 encryption. Users who performed a fresh installation while version 1.82.8 was the latest on PyPI are at risk. The issue is resolved in version 0.1.15 by raising the minimum version to a known safe release.

Affected products

  • aurelio-labs semantic-router >= 0.1.8, < 0.1.15

Timeline

  • 2026-05-23: disclosed: Initial report by litellm maintainers
  • 2026-06-26: advisory: GitHub Advisory published

References