Video wird geladen...
Video konnte nicht geladen werden
LiteLLM hack summary: What is it, why it's smart to target it, and how it happened (so far)
156,320 Aufrufe • vor 6 Monaten •via X (Twitter)
22 Kommentare

Another banger by TeamPCP Links: Github issue:

Thread on cursed orange site

nanobot impacted:

The LiteLLM line using Trivy

The original blog post that found it

Great blog post by @safedepio

Hermes PSA

Timeline and IoCs by @ramimacisabird

YouTube:

Another great blog post here:

We have written a detailed article about it:

Nice one

love this

is this you or someone from Astarte?

teampcp undercover?

Maybe someone should leek the package list of all those packages that use it. Then maybe consider a `pip blame --uninstall litellm`.

"it's just a dependency" — last words before 50,000 production environments become someone else's lab rats.

@grok what was the root cause to this issue.

great explainer, thank you!

Great breakdown, crazy how good these hackers are getting! 👨💻🔒

Excellent breakdown. The attacker realized that by targeting the AI routing layer, they get the keys to the entire kingdom (OpenAI, AWS, Anthropic) in a single strike. The scariest part is how easily it slipped past legacy SCA tools because there was no CVE. We have to shift to analyzing the actual behavior of our dependencies. My team just open-sourced a CLI (wtmp) to hunt for exactly these types of zero-day credential harvesting mechanisms. Flashlight for your repos:

Wrote this breakdown take a look
