flâneur — a map of the web's best reading

Snyk on X: "@karpathy The LiteLLM dependency incident didn't "just happen" though. This is part of a larger campaign LiteLLM already extends to supply chain security fallout for other projects: https://t.co/7bL3kNHP15" / X

x.com · 27 words · saved by 1 readers

To view keyboard shortcuts, press question mark View keyboard shortcuts Home Explore Notifications Follow Chat Grok Bookmarks Creator Studio Premium 50% off Profile More Post A Curious Mind @trdcjfhvkjbk Post See new posts Conversation Andrej Karpathy @karpathy · Mar 24 Software horror: litellm PyPI supply chain attack. Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database Show more Quote Daniel Hnyk @hnykda · Mar 24 LiteLLM HAS BEEN COMPROMISED, DO NOT UPDATE. We just discovered that LiteLLM pypi release 1.82.8. It has been compromised, it contains litellm_init.pth with base64 encoded instructions to send all the credentials it can find to remote server + self-replicate. link below 1.2K 6.1K 25K 52M Snyk @snyksec The LiteLLM dependency incident didn't "just happen" though. This is part of a larger campaign LiteLLM

@snyksec: The LiteLLM dependency incident didn't "just happen" though. This is part of a larger campaign LiteLLM already extends to supply chain security fallout for other projects:

Explore this link on the map →

saved by

related reading