Executive brief
Aurelio Labs semantic-router, a library for AI decision-making, was found to have a dependency configuration that allowed the installation of a compromised version of the litellm package. If a user installed semantic-router during a specific window in 2026, a malicious version of the dependency could have been automatically downloaded. This malicious code is designed to steal sensitive information, including cloud provider credentials (AWS/GCP/Azure), SSH keys, Kubernetes configurations, and database secrets, potentially leading to a full compromise of the user's environment.
Technical details
semantic-router versions 0.1.8 through 0.1.14 used an unbounded dependency pin (litellm>=1.61.3), which allowed the installation of a compromised 'litellm' wheel (version 1.82.8) from PyPI. The malicious wheel contains a 'litellm_init.pth' file that executes arbitrary Python code upon interpreter startup without requiring an explicit import. The payload exfiltrates environment variables, cloud credentials, SSH keys, and CI/CD secrets to a remote server (https://models.litellm.cloud/) using AES-256 encryption. Users who performed a fresh installation while version 1.82.8 was the latest on PyPI are at risk. The issue is resolved in version 0.1.15 by raising the minimum version to a known safe release.
Affected products
- aurelio-labs semantic-router >= 0.1.8, < 0.1.15
Timeline
- 2026-05-23: disclosed: Initial report by litellm maintainers
- 2026-06-26: advisory: GitHub Advisory published