Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised
439 by dot_treo | 362 comments on
About an hour ago new versions have been deployed to PyPI. I was just setting up a new project, and things behaved weirdly. My laptop ran out of RAM, it looked like a forkbomb was running. I've investigated, and found that a base64 encoded blob has been added to proxy_server.py. It writes and decodes another file which it then runs. I'm in the process of reporting this upstream, but wanted to give everyone here a headsup. It is also reported in this issue: https://ift.tt/cU6k3ih
Subscribe to:
Post Comments (Atom)
New best story on News: Desk for people who work at home with a cat
Desk for people who work at home with a cat 451 by zdw | 162 comments .
-
macOS unable to open any non-Apple application 769 by mattsolle | 467 comments on News.
-
Qualcomm and Apple agree to drop all litigation 467 by saeedjabbar | 122 comments on News.
-
SubEthaEdit 5 is now free and open source 357 by schwuk | 29 comments on
No comments:
Post a Comment