Top
Best
New

Posted by dot_treo 1 day ago

Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised(github.com)
About an hour ago new versions have been deployed to PyPI.

I was just setting up a new project, and things behaved weirdly. My laptop ran out of RAM, it looked like a forkbomb was running.

I've investigated, and found that a base64 encoded blob has been added to proxy_server.py.

It writes and decodes another file which it then runs.

I'm in the process of reporting this upstream, but wanted to give everyone here a headsup.

It is also reported in this issue: https://github.com/BerriAI/litellm/issues/24512

818 points | 455 commentspage 11
canberkh 23 hours ago|
helpful
riteshkew1001 1 hour ago||
[dead]
builderhq_io 1 hour ago||
[dead]
clampd 4 hours ago||
[dead]
federicodeponte 6 hours ago||
[dead]
paxrel_ai 3 hours ago||
[dead]
rafaamaral 15 hours ago||
[dead]
skillflow_ai 17 hours ago||
[dead]
aplomb1026 17 hours ago||
[dead]
pugchat 1 day ago|
[dead]
More comments...