#10
Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised
The Litellm 1.82.7 and 1.82.8 packages on PyPI were compromised with malicious code, affecting over 40,000 monthly downloads. Security scans uncovered a hidden backdoor that exfiltrates API keys, putting every LLM project at risk — 15% of all Hugging Face deployments now face potential breaches. With 2,400 GitHub stars, Litellm's users must act fast: reinstall from source or face a 100% likelihood of credential theft within 24 hours.
Photos (1)

Comments on "Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised"
Have a take on this ranking?
Comments are how the argument actually happens here. Posting one needs a free account — it takes about a minute.
No comments yet.
The first comment sets the terms of the argument.