Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised
51–60 of 569 posts
Re: Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised
#52Does anyone know a good alternate project that works similarly (share multipple LLMs across a set of users)? LiteLLM has been getting worse and trying to get me to upgrade to a paid version. I also had issues with creating tokens for other users etc.
Re: Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised
#53That's a bad supply-chain attack, many folks use litellm as main gateway
Re: Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised
#54Does anyone know a good alternate project that works similarly (share multipple LLMs across a set of users)? LiteLLM has been getting worse and trying to get me to upgrade to a paid version. I also had issues with creating tokens for other users etc.
Re: Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised
#55I'm sensing a pattern here, hmm.
Re: Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised
#56This is a brutal one. A ton of people use litellm as their gateway.
Do you feel as if people will update litellm without looking at this discussion/maybe having it be automatic which would then lead to loss of crypto wallets/ especially AI Api keys? Now I am not worried about the Ai Api keys having much damage but I am thinking of one step further and I am not sure how many of these corporations follow privacy policy and so perhaps someone more experienced can tell me but wouldn't th…
Irrevocable transfers... What could go wrong?
Re: Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised
#57Re: Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised
#58Do the labs label code versions with an associated CVE to label them as compromised (telling the model what NOT to do)? Do they do adversarial RL environments to teach what's good/bad? I'm very curious since it's inevitable some pwned code ends up as training data no matter what.
Re: Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised
#59That's why I'm building https://github.com/kstenerud/yoloai
Re: Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised
#60LiteLLM is the second worst software project known to man. (First is LangChain. Third is OpenClaw.) I'm sensing a pattern here, hmm.