Look like the Founder and CTO account has been compromised. https://github.com/krrishdholakia
Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised
21–30 of 569 posts
Re: Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised
#22good i was too lazy to bump versions
Re: Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised
#23Besides main issue here, and the owners account being possibly compromised as well, there's like 170+ low quality spam comments in there. I would expect better spam detection system from GitHub. This is hardly acceptable.
Re: Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised
#24Re: Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised
#25Re: Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised
#26Re: Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised
#27What is happening in this issue thread? Why are there 100+ satisfied slop comments?
Attackers trying to stifle discussion, they did the same for trivy: https://github.com/aquasecurity/trivy/discussions/10420
https://github.com/BerriAI/litellm/issues/24512#issuecomment...
Re: Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised
#28I hope that everyone's course of action will be uninstalling this package permanently, and avoiding the installation of packages similar to this.
In order to reduce supply chain risk not only does a vendor (even if gratis and OS) need to be evaluated, but the advantage it provides.
Exposing yourself to supply chain risk for an HTTP server dependency is natural. But exposing yourself for is-odd, or whatever this is, is not worth it.
Remember that you are programmers and you can just program, you don't need a framework, you are already using the API of an LLM provider, don't put a hat on a hat, don't get killed for nothing.
And even if you weren't using this specific dependency, check your deps, you might have shit like this in your requirements.txt and was merely saved by chance.
An additional note is that the dev will probably post a post-mortem, what was learned, how it was fixed, maybe downplay the thing. Ignore that, the only reasonable step after this is closing a repo, but there's no incentive to do that.