Snyk has reported that there have been attempts or successful attacks targeting this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade semantic-router to version 0.1.15 or higher.
semantic-router is a malicious package.
in the litellm_init.pth process. An attacker can gain unauthorized access to sensitive information, including environment variables, cloud credentials, SSH keys, database credentials, and other secrets, by executing malicious code during Python interpreter startup without requiring an import. The collected data is encrypted and exfiltrated to an external server. This is only exploitable if a fresh installation occurred during the period when the compromised dependency version was available on the package repository.
This vulnerability can be mitigated by explicitly pinning the dependency to a safe version, auditing the installation directory for malicious files, and rotating any potentially exposed credentials.