๐ณ๏ธโ๐ That Pup Crash! ๐พ
40.5K posts

๐ณ๏ธโ๐ That Pup Crash! ๐พ
@PupCrash
Hot takes on current events and computer science, served fresh, whenever I briefly forget this website is awful now




LiteLLM HAS BEEN COMPROMISED, DO NOT UPDATE. We just discovered that LiteLLM pypi release 1.82.8. It has been compromised, it contains litellm_init.pth with base64 encoded instructions to send all the credentials it can find to remote server + self-replicate. link below

New supply chain attack this time for npm axios, the most popular HTTP client library with 300M weekly downloads. Scanning my system I found a use imported from googleworkspace/cli from a few days ago when I was experimenting with gmail/gcal cli. The installed version (luckily) resolved to an unaffected 1.13.5, but the project dependency is not pinned, meaning that if I did this earlier today the code would have resolved to latest and I'd be pwned. It's possible to personally defend against these to some extent with local settings e.g. release-age constraints, or containers or etc, but I think ultimately the defaults of package management projects (pip, npm etc) have to change so that a single infection (usually luckily fairly temporary in nature due to security scanning) does not spread through users at random and at scale via unpinned dependencies. More comprehensive article: stepsecurity.io/blog/axios-comโฆ








JUST IN: NBC News poll reveals AI favorability at just 26% โ lower than ICE.



JUST IN: Petri dish of human brain cells grown on a microchip has learned to play DOOM.


Musk, CEO of Tesla and xAI, has said AGI will come this year.

