Golgafrinchan
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
cm0002@literature.cafe to cybersecurity@infosec.pub · 1 month ago

Supply Chain Attack in litellm 1.82.8 on PyPI

futuresearch.ai

external-link
message-square
1
fedilink
5
external-link

Supply Chain Attack in litellm 1.82.8 on PyPI

futuresearch.ai

cm0002@literature.cafe to cybersecurity@infosec.pub · 1 month ago
message-square
1
fedilink
litellm 1.82.8 Supply Chain Attack on PyPI (March 2026)
futuresearch.ai
external-link
litellm version 1.82.8 on PyPI contains a malicious .pth file that harvests SSH keys, cloud credentials, and secrets on every Python startup, then attempts lateral movement across Kubernetes clusters. First reported to PyPI by FutureSearch, whose report led to the package being quarantined.
alert-triangle
You must log in or register to comment.
  • Skullgrid@lemmy.world
    link
    fedilink
    arrow-up
    1
    ·
    30 days ago

    fucking supply chain attacks man.

cybersecurity@infosec.pub

cybersecurity@infosec.pub

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!

Community Rules

  • Be kind
  • Limit promotional activities
  • Non-cybersecurity posts should be redirected to other communities within infosec.pub.

Enjoy!

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 30 users / day
  • 345 users / week
  • 786 users / month
  • 2.07K users / 6 months
  • 1 local subscriber
  • 6.08K subscribers
  • 669 Posts
  • 918 Comments
  • Modlog
  • mods:
  • shellsharks@infosec.pub
  • tweedge@infosec.pub
  • BE: 0.19.10
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org