Search results for "PIP"
Today
03:52

A single pip install steals all keys: Karpathy calls LiteLLM supply chain poisoning "the most terrifying thing in software"

OpenAI member Karpathy has pointed out that the LiteLLM development tool suffered a supply chain attack, resulting in the theft of sensitive information such as user SSH keys. The compromised version has been removed from PyPI, and the malicious code could cause widespread data leaks through simple installation. The attack persisted for approximately 1 hour after being exposed. The development team has taken measures to prevent recurrence.
More