This would also disable site import so not viable generically for everyone without testing.
Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised
41–50 of 569 posts
Re: Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised
#42Re: Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised
#43Look like the Founder and CTO account has been compromised. https://github.com/krrishdholakia
Re: Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised
#44I guess I am lucky as I have watchtower automatically update all my containers to the latest image every morning if there are new versions.
I also just added it to my homelab this sunday, I guess that's good timing haha.
Re: Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised
#45Re: Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised
#46Re: Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised
#47Re: Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised
#48Re: Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised
#49This is a brutal one. A ton of people use litellm as their gateway.
Now I am not worried about the Ai Api keys having much damage but I am thinking of one step further and I am not sure how many of these corporations follow privacy policy and so perhaps someone more experienced can tell me but wouldn't these applications keep logs for legal purposes and those logs can contain sensitive information, both of businesses but also, private individuals perhaps too?