
Jeremiah Clark
737 posts

Jeremiah Clark
@JeremiahOClark
Building AI tools that make you better at what you do | become better with data @ https://t.co/8QmiMglGxM



🚨 Supply chain attack on the Laravel Lang organization: 700+ historical versions across multiple community-maintained Laravel Lang packages were compromised with an RCE backdoor, including: laravel-lang/lang laravel-lang/http-statuses laravel-lang/attributes Laravel-Lang/actions The payload targets cloud creds, CI/CD secrets, Kubernetes tokens, Vault, browser data, password managers, SSH keys, and more.






@JeremiahOClark @NousResearch we added an extra prevention layer after that also, any PR with base64 in them will now be flagged immediately as extra sus (which is apparently what happened to litellm)
















Thank you Luba for notifying us as well as the discord community of @Lite_LLM having been hacked. Please see this important security notice if you are a Hermes Agent user who installed within the last 4-24 hours!




