LiteLLM Compromised on PyPI: How a Hijacked Maintainer Account Turned an LLM Gateway Into a Credential Stealer