Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised
443 by dot_treo | 363 comments on News.
About an hour ago new versions have been deployed to PyPI. I was just setting up a new project, and things behaved weirdly. My laptop ran out of RAM, it looked like a forkbomb was running. I've investigated, and found that a base64 encoded blob has been added to proxy_server.py. It writes and decodes another file which it then runs. I'm in the process of reporting this upstream, but wanted to give everyone here a headsup. It is also reported in this issue: https://ift.tt/4o6NiQl
Subscribe to:
Post Comments (Atom)
New best story on Hacker News: Omarchy: Any User Process Can Escalate to Root
Omarchy: Any User Process Can Escalate to Root 391 by trap0xcc | 397 comments on
-
Next.js is infuriating 843 by Bogdanp | 473 comments .
-
France to ditch Windows for Linux to reduce reliance on US tech 451 by Teever | 185 comments on
-
Deep Reinforcement Learning: Zero to Hero 484 by alessiodm | 43 comments on News.
No comments:
Post a Comment