This domain is a confirmed malicious endpoint used in a supply chain attack against the litellm Python library. It facilitates the exfiltration of stolen credentials and sensitive system data from compromised environments.
- Specialization
- Data Exfiltration Endpoint
- Registered
- Mar 23, 2026