Best AI News — Updated Every 3 Hours
Story Page
← All Stories
Home Community Story
Community

[D] Litellm supply chain attack and what it means for api key management

Via r/MachineLearning
Saturday, Mar 28, 2026 · 3:07PM
Summary

If you missed it, litellm versions 1.82.7 and 1.82.8 on pypi got compromised. malicious .pth file that runs on every python process start, no import needed. it scrapes ssh keys, aws/gcp creds, k8s secrets, crypto wallets, env vars (aka all your api keys). karpathy posted about it. the attacker got i

Continue reading the full article
Read at r/MachineLearning
www.reddit.com
Back to all stories