Krishu

14.2K posts

Krishu

Krishu

@KrishuScion

Developer | Startup | IITian | Cricket

Katılım Şubat 2022
334 Takip Edilen83 Takipçiler
Krishu
Krishu@KrishuScion·
@Wellutwt This really feels like achhe din compared to that shit😂
English
0
0
4
325
Krishu
Krishu@KrishuScion·
@manthanguptaa AI safety over open source repo is needed, it should be easy to get a scan of the code you are installing with AI isn’t it?
English
1
0
0
85
Manthan Gupta
Manthan Gupta@manthanguptaa·
The LiteLLM supply chain attack is honestly terrifying. A simple pip install litellm was enough to execute malicious code on your machine. Not even on import in one of the versions, it ran on every Python startup using a .pth trick. So just having it installed was enough to get compromised. And the payload wasn’t small either. It was scanning for SSH keys, cloud credentials, Kubernetes configs, environment variables, database passwords, shell history, and basically anything valuable on your machine and shipping it out. What’s worse is how it got there. This wasn’t some random package getting hijacked. The attacker compromised upstream infrastructure and pushed malicious versions directly to PyPI. So even if you trust the repo, the release pipeline itself was compromised. And like always with these attacks, you didn’t even need to install it directly. If it sat anywhere in your dependency tree, you were exposed. That's the real problem with how we build software today. One compromised package and it quietly propagates everywhere. The whole thing was live only for a few hours, but that’s more than enough. CI pipelines, local machines, production systems, everything installs the latest versions all the time. The craziest part is how it got caught. One of the versions had a bug that caused machines to run out of memory and crash. That’s what surfaced it. If that bug didn’t exist, this could’ve gone unnoticed for much longer. That’s the part that should worry everyone. Not just that it happened, but how easily it could’ve stayed invisible. We have basically built a system where pip install is equivalent to running arbitrary code from the internet, dependencies are chains of blind trust, and we execute all of this in environments full of secrets. And then we do this hundreds of times per project without thinking twice. The AI ecosystem just makes this worse. Tools like LiteLLM sit deep in the stack and have access to high-value credentials by default. Compromise that layer, and you get everything. At some point, the idea that dependencies are safe building blocks needs to be rethought. Because in reality, every dependency is a potential entry point. We have made building software insanely fast. We have also made it insanely fragile.
Daniel Hnyk@hnykda

LiteLLM HAS BEEN COMPROMISED, DO NOT UPDATE. We just discovered that LiteLLM pypi release 1.82.8. It has been compromised, it contains litellm_init.pth with base64 encoded instructions to send all the credentials it can find to remote server + self-replicate. link below

English
7
3
48
9.3K
Krishu
Krishu@KrishuScion·
@The_Sleigher Current generation donot know why Rahul gandhi was called pappu
English
0
0
0
52
Abhishek
Abhishek@abhishekcode42·
It used to be the greatest show of human history after the first 4 seasons. How they massacred my boy after that, and the downfall started from season 5. But yeah, still, the first 4 seasons are absolute cinmea peak writing, would recommend for sure.
Abhishek tweet media
English
16
2
152
71.5K
Krishu
Krishu@KrishuScion·
@jamilmusman_ Are these the captains of psl league teams, man Pakistan really don’t have players 🤦‍♂️ It’s the same 4-5 faces everywhere
English
1
0
19
6.5K
Usman
Usman@jamilmusman_·
This has to be one of the worst captain photoshoot with the trophy in the history of league cricket…
Usman tweet media
English
58
34
1.2K
131.2K
Krishu
Krishu@KrishuScion·
@Shahrcasm Only because there was Akshaye khanna
GIF
English
0
1
3
82
Babu Bhaiya
Babu Bhaiya@Shahrcasm·
I will be cancelled for my opinion but Dhurandhar 1 > Dhurandhar 2
English
85
26
546
34.1K
Krishu
Krishu@KrishuScion·
@SAMTHEBESTEST_ I think he must have been contacted for Dawood role, he has moustache and lookalike like him
English
0
0
4
2K
$@M
$@M@SAMTHEBESTEST_·
"#AdityaDhar came to me for #Dhurandhar2. He wanted me to do a small cameo in the film. But the reason I am what I am today is because of my professionalism and my commitment. It’s my loss." - #AnilKapoor
$@M tweet media
English
30
77
3.2K
304.5K
Netflix Brasil
Netflix Brasil@NetflixBrasil·
01001111 00100000 01000010 01010010 01000001 01010011 01001001 01001100 00100000 01010110 01000001 01001001 00100000 01000001 01010010 01001001 01010010 01000001 01001110 01000111 01000001 01010010
2.9K
5.8K
46.5K
22M
Wisden
Wisden@WisdenCricket·
Abrar Ahmed, the No.3 ranked T20I bowler in the world, will feature in The Hundred for Sunrisers Leeds. There had been fears that Pakistani players would be excluded by IPL-backed teams in the weeks leading up to the auction. #TheHundred
Wisden tweet media
English
80
33
540
51.5K
Lawrence Booth
Lawrence Booth@BoothCricket·
A big moment as Sunrisers Leeds (one of the Hundred teams with IPL connections) bid for Pakistan leg-spinner Abrar Ahmed.
English
64
42
763
69K
Krishu
Krishu@KrishuScion·
@idhruvrathore Koi bhi movie India mein 1000cr ke budget mein nhi banni chaiye simple, yeh toh 4000cr mein ban rhi 🫡
Indonesia
1
0
3
526
Dhruv
Dhruv@idhruvrathore·
Ramayana ko leke jitne sapne dekhe the unko dafna do to hi accha hai
हिन्दी
18
4
404
46K
Krishu
Krishu@KrishuScion·
@GovindIstSTH First 90 minutes of a morning test match is miles more exciting than this passing the ball fraud sport
English
0
0
101
3.8K
DICKIPEDIA
DICKIPEDIA@dickipedia_·
@ZacksJerryRig The question you should ask why do they have a school literally inside an active military compound lmao
English
7
0
10
7.2K
Krishu
Krishu@KrishuScion·
@GabbbarSingh Iran was kept out of global economy, so they don’t care whether global economy tank or not. This is a war for survival for them. They are not a chimp, it’s united states which with a half brain pedophile attacked iran with no exit plan
English
0
0
1
84
Krishu
Krishu@KrishuScion·
@MirabelTweets1 The American propaganda worked for 70 fucking years on these imbeciles , they have sub zero iq, they elected a pedophile , brain dead , crazy person as their president knowing full well who is he . They are complicit in this, they are child murderers
English
0
0
0
11
Stop The Bollocks with Mirabel
Stop The Bollocks with Mirabel@MirabelTweets1·
Have all Americans been lobotomized? Or was there something in that vaccine? The leader of your country is a paedophile committing war crimes & you’re sat on your arses watching Netflix
English
281
1.8K
10.1K
111.6K
Krishu
Krishu@KrishuScion·
@KimDotcom Each and every American who voted for Donald trump is a murderer
English
0
0
0
26
Kim Dotcom
Kim Dotcom@KimDotcom·
Insane
Türkçe
279
4.2K
10.1K
269.6K