LiteLLM PyPI has been compromised an hour ago, do not update

Bullhorn9268 23 points 4 comments March 24, 2026
futuresearch.ai · View on Hacker News

Discussion Highlights (2 comments)

rgambee

It's also been reported to their GitHub: https://github.com/BerriAI/litellm/issues/24512

darkteflon

We recently switched to pnpm, in part to guard against supply chain attacks ( https://pnpm.io/supply-chain-security ). Reading this got me wondering whether uv has something similar, and indeed it does appear to ( https://docs.astral.sh/uv/reference/settings/#exclude-newer )

Semantic search powered by Rivestack pgvector
3,471 stories · 32,344 chunks indexed