Loading video...

Video Failed to Load

Go Home

LiteLLM hack summary: What is it, why it's smart to target it, and how it happened (so far)

156,320 views • 6 months ago •via X (Twitter)

22 Comments

solst/ICE of Astarte's profile picture
solst/ICE of Astarte6 months ago

Another banger by TeamPCP Links: Github issue:

solst/ICE of Astarte's profile picture
solst/ICE of Astarte6 months ago

Thread on cursed orange site

solst/ICE of Astarte's profile picture
solst/ICE of Astarte6 months ago

nanobot impacted:

solst/ICE of Astarte's profile picture
solst/ICE of Astarte6 months ago

The LiteLLM line using Trivy

solst/ICE of Astarte's profile picture
solst/ICE of Astarte6 months ago

The original blog post that found it

solst/ICE of Astarte's profile picture
solst/ICE of Astarte6 months ago

Great blog post by @safedepio

solst/ICE of Astarte's profile picture
solst/ICE of Astarte6 months ago

Hermes PSA

solst/ICE of Astarte's profile picture
solst/ICE of Astarte6 months ago

Timeline and IoCs by @ramimacisabird

solst/ICE of Astarte's profile picture
solst/ICE of Astarte6 months ago

YouTube:

solst/ICE of Astarte's profile picture
solst/ICE of Astarte6 months ago

Another great blog post here:

Precogs AI's profile picture
Precogs AI6 months ago

We have written a detailed article about it:

solst/ICE of Astarte's profile picture
solst/ICE of Astarte6 months ago

Nice one

mRr3b00t's profile picture
mRr3b00t6 months ago

love this

Ac1d's profile picture
Ac1d6 months ago

is this you or someone from Astarte?

Ac1d's profile picture
Ac1d6 months ago

teampcp undercover?

Jacko ⚡️'s profile picture
Jacko ⚡️6 months ago

Maybe someone should leek the package list of all those packages that use it. Then maybe consider a `pip blame --uninstall litellm`.

MAKVision's profile picture
MAKVision6 months ago

"it's just a dependency" — last words before 50,000 production environments become someone else's lab rats.

👩🏻‍💻 JustAskPenny's profile picture
👩🏻‍💻 JustAskPenny6 months ago

@grok what was the root cause to this issue.

JP Aumasson's profile picture
JP Aumasson6 months ago

great explainer, thank you!

MiamiCanes's profile picture
MiamiCanes6 months ago

Great breakdown, crazy how good these hackers are getting! 👨‍💻🔒

Zulfikar Ramzan (He / Him)'s profile picture
Zulfikar Ramzan (He / Him)6 months ago

Excellent breakdown. The attacker realized that by targeting the AI routing layer, they get the keys to the entire kingdom (OpenAI, AWS, Anthropic) in a single strike. The scariest part is how easily it slipped past legacy SCA tools because there was no CVE. We have to shift to analyzing the actual behavior of our dependencies. My team just open-sourced a CLI (wtmp) to hunt for exactly these types of zero-day credential harvesting mechanisms. Flashlight for your repos:

Unicity's profile picture
Unicity6 months ago

Wrote this breakdown take a look

Related Videos