Zenity Labs
aidefend-sf0008
LiteLLM Connection-Test Key Exfiltration via Nested api_base
- AI Infrastructure
- Data Exfiltration
- Credential & Identity Theft
Zenity Labs recorded 2,721 LiteLLM admin requests from April 7 through June 1, 2026. The dominant path sent 2,704 nested /health/test_connection requests that paired an attacker-controlled api_base with api_key: os.environ/LITELLM_MASTER_KEY; Zenity reproduced the proxy resolving the environment reference and transmitting the real key to a collector. Sixteen /chat/completions requests instead aimed api_base at cloud instance metadata. One /model/new request stored a loopback api_base, but the source does not show that route later being used. The flow preserves all three paths and their different evidence limits.