I did not expect this ending

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

A major Python supply chain attack hit LiteLLM, a popular LLM proxy package downloaded 97 million times monthly. Hackers compromised the LiteLLM GitHub repository and pushed a malicious version that exfiltrated SSH keys, cloud credentials, database passwords, and more via a Python .pth file executed at interpreter startup. The attack was accidentally discovered when a user's machine crashed from a fork bomb caused by the malicious code. The GitHub issue was then flooded with AI-generated bot spam to suppress visibility. A final twist: LiteLLM's compliance certifications were provided by Delve, a company itself accused of issuing fake SOC 2 reports — and both are Y Combinator-backed. The threat actor claims 500,000 stolen credentials from LiteLLM alone and is actively extorting multi-billion dollar companies.

8m watch time

Sort: