Decision RecordActivePublished without chair review
CRT-2026-024418 Aug 2026MORNING EDITIONDaily Roundtable
Contain reported backdoored LiteLLM releases
Quarantine LiteLLM versions 1.82.7 and 1.82.8, preserve build and runtime evidence, rebuild from verified trusted artifacts, and rotate or revoke reachable credentials from a clean system.
Current public guidance · the full record
What to do now
At a glanceThe edition's authoritative action board carries no action for this record's subjects — no What to do now guidance.
Why now
WeakAs of August 18, 2026, the bounded Roundtable evidence reported malicious content in the PyPI releases LiteLLM 1.82.7 and LiteLLM 1.82.8 that was absent from the upstream repository.
Installation already establishes exposure even though execution remains unresolved. Immediate quarantine limits continued use, while preserving build and runtime evidence before rebuilding allows each environment to determine whether execution or credential access occurred.
Who is affected
Under reviewCI and build systems that installed LiteLLM 1.82.7 or LiteLLM 1.82.8 have package and build-pipeline exposure, including possible access to reachable build credentials.
Developer workstations with either version installed have local execution exposure and possible access to developer credentials. Runtime deployments using either version have possible payload-execution exposure and possible access to runtime credentials or connected services.
Operators of each exposed environment must preserve the corresponding build or runtime evidence, rebuild from trusted artifacts, and rotate or revoke credentials reachable from that environment.
What supports this
SupportedPackage-content report — supports: reports malicious content in the LiteLLM 1.82.7 and LiteLLM 1.82.8 wheels that was absent from the upstream repository.
Source-to-distribution analysis — supports: describes an integrity failure and specific runtime indicators, supporting evidence preservation and investigation.
Operational response evidence — supports: consistently recommends quarantine, trusted rebuilding, and rotation or revocation of reachable credentials from a clean system.
Release-evidence audit — evidence gap: finds no vendor release evidence naming a clean replacement; this limits the replacement target but does not contradict immediate containment.
How the Roundtable reached this
Under reviewThe supply-chain assessment surfaced malicious wheel content in LiteLLM 1.82.7 and LiteLLM 1.82.8 that was reportedly absent from the upstream repository.
The evidence audit supported quarantine, evidence preservation, trusted rebuilding, and credential rotation, while flagging the absence of vendor evidence naming a clean replacement.
The boundary review resolved the central wording issue: installation establishes exposure but does not prove payload execution in every environment.
A record search found no prior Decision Record, and the arbiter selected a new operational decision because the replacement-version gap did not block immediate containment.
Positions are generated by AI specialist personas and chaired by Halil Öztürkci.
Panel composition
- Scout (AI panel role)Scout identified 5 candidate signals.
- Linker (AI panel role)Linker evaluated 5 relation judgments.
- Evidence Auditor (AI panel role)Evidence Auditor recorded 12 evidence signals; 7 gaps.
- Prediction Steward (AI panel role)Prediction Steward accepted 0 predictions and rejected 2 claims.
- Boundary Reviewer (AI panel role)Boundary Reviewer recorded 10 public/private findings.
- Arbiter (AI panel role)Arbiter produced 5 decision envelopes.
Key disagreement
Scout (AI panel role)
Installation establishes exposure, but payload execution and access to usable credentials are not established for every environment. | Merged related signal (candidate-4): Should organizations broadly stop npm publishing because of ChainDrop, or take exposure-based action? | Merged related signal (candidate-5): What action is required for the authenticated Active Directory Certificate Services domain-takeover path?
Arbiter outcome
Arbiter outcome: new decision record. The evidence supports immediate containment of the two reported malicious releases, preservation of evidence, trusted rebuilding, and credential rotation. The unidentified clean replacement version is an enrichment gap rather than a blocker, and no existing record was retrieved.
Candidates considered
Considered 5 candidates · opened 1 · 4 not opened (4 other)
Considered, not opened
Sign in to preview Considered-Not-Opened entries (moves to Pro at launch).
Sign in to preview practitioner entries.
What is uncertain
MissingInstallation of LiteLLM 1.82.7 or LiteLLM 1.82.8 establishes exposure, not confirmed execution.
The packet does not determine which installations executed the reported content or which credentials were reachable or accessed. It also does not identify a specific clean replacement version or provide vendor confirmation that only 1.82.7 and 1.82.8 were affected.
What evidence is missing
MissingThe packet lacks vendor release evidence that names an approved clean LiteLLM replacement version or artifact and confirms whether the affected-version boundary is limited to LiteLLM 1.82.7 and LiteLLM 1.82.8. It also does not establish, for any particular CI system, developer workstation, or runtime deployment, whether the payload executed, created persistence, generated network activity, or accessed usable credentials.
What would change this
Under reviewVendor evidence that changes the affected-version boundary would change which LiteLLM installations require quarantine.
Vendor evidence naming a clean replacement would replace the current generic requirement to rebuild from verified trusted artifacts. Proof that a system never installed LiteLLM 1.82.7 or LiteLLM 1.82.8 would remove that system from scope.
Evidence of execution, persistence, network activity, or credential access would escalate that environment from precautionary containment to full incident response and broader credential revocation.
What to watch next
Under reviewSearch quarantined LiteLLM 1.82.7 and LiteLLM 1.82.8 environments for package hashes, modified files, persistence, and network indicators.
If evidence confirms execution, start full incident response and expand credential revocation beyond credentials merely known to be reachable.
Watch for vendor release evidence naming an approved clean replacement and confirming the affected-version boundary; use it to revise rebuild targets and inventory scope.
Evidence basis
Tonight, run three parallel tracks: - **Coldcard:** For the specified vulnerable firmware generations, generate a new seed using corrected firmware or another trusted device and migrate funds immediately; firmware updates cannot repair an a…
**ChainDrop:** Microsoft and StepSecurity report that attackers controlled legitimate GitHub release workflows, pushing poisoned commits/tags and publishing through npm Trusted Publishing. The resulting artifacts could carry valid OIDC-back…
Summary: Coldcard is today’s most irreversible risk: Coinkite’s advisory indicates affected seeds must be replaced, not merely patched. CISA-confirmed PTC exploitation and reported SAP exploitation attempts demand compromise assessment, alt…
Public value history
- 18 Aug 2026Initial public guidanceCurrent guidance
Created the first public value version for this Decision Record.
Source RoundtableMorning roundtableConvened 18 Aug 2026Methodology
How the panel reaches a Public Decision Record.