TheVSpotNews

530 posts

TheVSpotNews banner
TheVSpotNews

TheVSpotNews

@VCoconsulting

Weekly news around the world of ecommerce, retail & technology. Host of the V Spot - home to the eCommerce Nearly News. https://t.co/0G1S11GEMC

Tralee 가입일 Mart 2019
2.2K 팔로잉243 팔로워
TheVSpotNews 리트윗함
TheVSpotNews 리트윗함
tobi lutke
tobi lutke@tobi·
New version of Universal Commerce Protocol (UCP 2026-04-08) just got finalized. Carts (!), Catalog discovery features, Order status,, Signals support, ... Big step step function upgrade for agentic commerce. ucp.dev/2026-04-08/spe… Coming soon to every Shopify storefront.
English
21
33
416
36.6K
TheVSpotNews 리트윗함
Tuki
Tuki@TukiFromKL·
🚨 Andrej Karpathy just explained the scariest thing happening in software right now.. someone poisoned a Python package that gets 97 million downloads a month.. and a simple pip install was enough to steal everything on your machine.. SSH keys.. AWS credentials.. crypto wallets.. database passwords.. git credentials.. shell history.. SSL private keys.. everything.. and here's the part that should terrify every developer alive.. the attack was only discovered because the attacker wrote sloppy code.. the malware used so much RAM that it crashed someone's computer.. if the attacker had been better at coding.. nobody would have noticed for weeks.. one developer.. using Cursor with an MCP plugin.. had litellm pulled in as a dependency they didn't even know about.. their machine crashed.. and that crash saved thousands of companies from getting their entire infrastructure stolen.. Karpathy's take is the real wake up call.. every time you install any package you're trusting every single dependency in its tree.. and any one of them could be poisoned.. vibe coding saved us this time.. the attacker vibe coded the attack and it was too sloppy to work quietly.. next time they won't make that mistake.
Andrej Karpathy@karpathy

Software horror: litellm PyPI supply chain attack. Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords. LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm. Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery - Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks. Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages. Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible.

English
282
2.3K
14K
3.2M
TheVSpotNews 리트윗함
Garda Info
Garda Info@gardainfo·
A new virus has arrived which targets the system that powers Apple devices. Here’s what you need to know 👇 Victims of the malware should consult a competent cyber security professional and report the crime to their local Garda Station. #KeepingPeopleSafe
Garda Info tweet media
English
26
97
284
111.9K
TheVSpotNews 리트윗함
Ros Atkins
Ros Atkins@BBCRosAtkins·
Two minutes on Donald Trump's mixed messages on the war with Iran. Produced by Katerina Karelli. The BBC News live page on the war is here: bbc.co.uk/news/live/ce84…
English
83
738
2K
324.9K
TheVSpotNews
TheVSpotNews@VCoconsulting·
@rcbregman Read Empire of AI - he should be no where near any of this.
English
0
0
0
17
TheVSpotNews
TheVSpotNews@VCoconsulting·
What would Malcolm Tucker make of the world today. Shows that would struggle to come up with scripts today but could be reality shows - Silicon Valley Veep The Thick of It
English
0
0
0
10
TheVSpotNews 리트윗함
Rugby World
Rugby World@Rugbyworldmag·
That’s going to be some kit to win a Grand Slam in.
English
7
72
1K
90.6K
TheVSpotNews 리트윗함