LiteLLM PyPI has been compromised an hour ago, do not update

27 points
1/21/1970
2 days ago
by Bullhorn9268

Comments


[deleted]
2 days ago

darkteflon

We recently switched to pnpm, in part to guard against supply chain attacks (https://pnpm.io/supply-chain-security).

Reading this got me wondering whether uv has something similar, and indeed it does appear to (https://docs.astral.sh/uv/reference/settings/#exclude-newer)

2 days ago

nateb2022

Wherever practical, I also recommend using devcontainers, so that in addition to breaking supply chain security, large-scale damage would require an unpatched sandbox exploit too.

a day ago

rgambee

It's also been reported to their GitHub: https://github.com/BerriAI/litellm/issues/24512

2 days ago

Bullhorn9268

yeah, updated in the post

2 days ago

parad0x0n

Thank you!

2 days ago

[deleted]
15 hours ago

Mooshux

[dead]

a day ago