Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Brite)
  • No Skin
Collapse
A microphone in front of an orange-yellow circle. Graphic.

Podcasting Chat Community

  1. Home
  2. General Podcast Discussion
  3. https://futuresearch.ai/blog/litellm-pypi-supply-chain-attack/
Podcasting.Chat Banner

https://futuresearch.ai/blog/litellm-pypi-supply-chain-attack/

Scheduled Pinned Locked Moved General Podcast Discussion
2 Posts 2 Posters 1 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • Adam Curry :pci: :pc2blue:A This user is from outside of this forum
    Adam Curry :pci: :pc2blue:A This user is from outside of this forum
    Adam Curry :pci: :pc2blue:
    wrote last edited by
    #1

    Link Preview Image
    Supply Chain Attack in litellm 1.82.8 on PyPI

    litellm version 1.82.8 on PyPI contains a malicious .pth file that harvests SSH keys, cloud credentials, and secrets on every Python startup, then attempts lateral movement across Kubernetes clusters. First reported to PyPI by FutureSearch, whose report led to the package being quarantined.

    favicon

    FutureSearch (futuresearch.ai)

    DaveD 1 Reply Last reply
    1
    0
    • podcastindex.socialI podcastindex.social shared this topic
    • Adam Curry :pci: :pc2blue:A Adam Curry :pci: :pc2blue:

      Link Preview Image
      Supply Chain Attack in litellm 1.82.8 on PyPI

      litellm version 1.82.8 on PyPI contains a malicious .pth file that harvests SSH keys, cloud credentials, and secrets on every Python startup, then attempts lateral movement across Kubernetes clusters. First reported to PyPI by FutureSearch, whose report led to the package being quarantined.

      favicon

      FutureSearch (futuresearch.ai)

      DaveD This user is from outside of this forum
      DaveD This user is from outside of this forum
      Dave
      wrote last edited by
      #2

      @adam Lol. I love how they throw in an ad for their product at the end of this security advisory:

      πŸ™„

      Link Preview Image
      1 Reply Last reply
      1
      0

      Hello! It looks like you're interested in this conversation, but you don't have an account yet.

      Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

      With your input, this post could be even better πŸ’—

      Register Login
      Reply
      • Reply as topic
      Log in to reply
      • Oldest to Newest
      • Newest to Oldest
      • Most Votes



      Welcome To Podcasting.Chat!

      This forum is for podcasters, podcast guests, and podcast enthusiasts alike to share tips, tricks, and their love of the medium.

      This forum is fully federated, so you are able to contribute to any discussion here through your own software of choice (e.g. Mastodon, Misskey, Lemmy, Piefed, etc.). So you can sign up for an account here and it federates around the Fediverse. You can also follow feeds and topics from your other Fedi-enabled accounts.





      Recent Posts


      • Podnews podcasting newsP
        Podnews podcasting news

        Starting soon: How to Know if Your Podcast is Working (Is it supporting your business yet?) (virtual) (free) https://podnews.net/event/how-to-know-if-your-podcast-is-working-is-it-supporting-your-business-yet #podevents

        read more

      • Mike KelleyM
        Mike Kelley

        @adam @dave @aegrumet @theDanielJLewis I would suspect the reason you're seeing higher toking usage in Claude is because the the maximum context window for gpt 5.3 is 400k where the maximum contacts window of Claude 4.6 is 1 million. Therefore, it has the ability to send a whole lot more information per prompt request. The beast is hungry and it loves to be fed!

        read more

      • eVOTErra – #RhRRE
        eVOTErra – #RhRR

        @donburnside

        You upload the audio files, just like you upload a photo or video!

        (Though it’s thru the gear icon… for now.)

        read more

      • Daniel J. LewisT
        Daniel J. Lewis

        @adam @dave @aegrumet 😎

        Link Preview Image
        read more

      A Goldstein Media LLC Project
      • Login

      • Don't have an account? Register

      • Login or register to search.
      • First post
        Last post
      0
      • Categories
      • Recent
      • Tags
      • Popular
      • World
      • Users
      • Groups