Snyk on X: "@karpathy The LiteLLM dependency incident didn't "just happen" though. This is part of a larger campaign LiteLLM already extends to supply chain security fallout for other projects: https://t.co/7bL3kNHP15" / X
To view keyboard shortcuts, press question mark View keyboard shortcuts Home Explore Notifications Follow Chat Grok Bookmarks Creator Studio Premium 50% off Profile More Post A Curious Mind @trdcjfhvkjbk Post See new posts Conversation Andrej Karpathy @karpathy · Mar 24 Software horror: litellm PyPI supply chain attack. Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database Show more Quote Daniel Hnyk @hnykda · Mar 24 LiteLLM HAS BEEN COMPROMISED, DO NOT UPDATE. We just discovered that LiteLLM pypi release 1.82.8. It has been compromised, it contains litellm_init.pth with base64 encoded instructions to send all the credentials it can find to remote server + self-replicate. link below 1.2K 6.1K 25K 52M Snyk @snyksec The LiteLLM dependency incident didn't "just happen" though. This is part of a larger campaign LiteLLM
@snyksec: The LiteLLM dependency incident didn't "just happen" though. This is part of a larger campaign LiteLLM already extends to supply chain security fallout for other projects:
saved by
related reading
- Security incident disclosure — July 2026huggingface.co
- Ultralytics AI Library Hacked via GitHub for Cryptomining | Wiz Blogwiz.io
- The lethal trifecta for AI agents: private data, untrusted content, and external communicationsimonwillison.net
- Countering misuse of AI: September 2026 / Anthropicanthropic.com
- Illustrating Reinforcement Learning from Human Feedback (RLHF)huggingface.co
- The Smol Training Playbook - a Hugging Face Space by HuggingFaceTBhuggingface.co
- Lakera – Test your AI hacking skillsgandalf.lakera.ai
- llm-security/README.md at main · greshake/llm-securitygithub.com
- OpenAI – Hugging Face Incident Technical Reportcdn.openai.com
- we have a year to fix security everywherejyn.dev
- [2608.09867] Stealing Reasoning Traces from Proprietary LLM APIsarxiv.org
- Dependency Confusion: How I Hacked Into Apple, Microsoft and Dozens of Other Companies | by Alex Birsan | Mediummedium.com