Azeem Shaikh retweetledi
Azeem Shaikh
8.8K posts

Azeem Shaikh
@shaikh_azeem
Restless • Analytical • Reserved • Efficient • Curious | Senior Solutions Architect
London, England Katılım Nisan 2011
2.6K Takip Edilen388 Takipçiler
Azeem Shaikh retweetledi
Azeem Shaikh retweetledi

Software horror: litellm PyPI supply chain attack.
Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords.
LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm.
Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery - Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks.
Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages.
Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible.
Daniel Hnyk@hnykda
LiteLLM HAS BEEN COMPROMISED, DO NOT UPDATE. We just discovered that LiteLLM pypi release 1.82.8. It has been compromised, it contains litellm_init.pth with base64 encoded instructions to send all the credentials it can find to remote server + self-replicate. link below
English

Check out my latest article: Will Human-Reasoned Code Become the New Swiss Watch? linkedin.com/pulse/human-re… via @LinkedIn
English

@ganeshsonawane Does the previous stock have durability issues? I just purchased 1 a few days ago
English
Azeem Shaikh retweetledi

Was talking to a Polish American friend who took retirement recently. Asked him if he is going to travel the world. He said he prefers traveling within US and Canada visiting the National parks and Alaska in future. He has turned a new Toyota Sequoia into a mini camper. This is just an American thing.
America is huge with endless roads, excellent camping options, inexpensive gas (compared to Europe especially- gas price in US - gallon less than $3. Europe, the liter price converted into gallon - $7:60 to $9.80/gallon depending on the country), ease of language convenience, safety and the range of terrains from beaches to deserts to mountains to plateaus, glaciers and geysers make Americans not look beyond US. They might add Canada but otherwise they are a contented travelers.
Girl patriot 🙏 🇺🇸 🦅@Girlpatriot1974
A British man explains to people in the UK why Americans aren't "well traveled." "Americans don't need to venture outside of America because America is that big. Americans go on vacation in America...I don't think Europeans are clued up on how big America really is.. Every single state in America is like it's own country."
English
Azeem Shaikh retweetledi

🚨 Did You Know: 10 years ago, Infosys was one of the earliest backers of OpenAI. They invested alongside Elon Musk, Peter Thiel, AWS, and others ($1B → ~$45B today).
Instead of doubling down, they fired their CEO Vishal Sikka, and now their stake is worth nothing.
How could this possibly happen? Who is Vishal? More below:

English

Want to win this gaming bundle?
📷Steam Deck, @ASUS ROG Swift 27" 4K 240Hz, @Logitech G920, & more!📷
To enter:
1. Follow @NVIDIAGFN
2. Reply with #BlackwellonGFN
3. Think back to your OG GFN setup & share 📸 : Which was the first device you turned into a GeForce gaming rig?
English

Want a chance to win this ultimate gamer bundle?
✨Steamdeck,@ASUS ROG Swift 27" 4K 240Hz G-SYNC Monitor, @Logitech G920, & more!✨
How to enter👇
1. Follow @NVIDIAGFN
2. Reply using #BlackwellonGFN
3. Tell us which #BlackwellonGFN announcement you're most excited about.
English
Azeem Shaikh retweetledi

GeForce RTX PC Week - FREE PC DROP 🔔
WIN this SFF @FalconNW gaming PC featuring:
🟢 GPU: GeForce RTX 5080 Founders Edition
🟢 CPU: Ultra 9 285K
🟢 RAM: 96GB Kingston Fury DDR5
🟢 PSU: Silverstone 1200W
Reply "GeForce PC Week" to enter!
English
Azeem Shaikh retweetledi

✨Announcing LangExtract! ✨
Our new open-source Python library for information extraction, powered by #Gemini.
✅ Turn text into structured data
✅ Trace every insight to its source
✅ Visualize results instantly
Explore the blog by @AkshayGoelMD and Atilla: goo.gle/3J90UcE
#DevTools #MachineLearning #Python

English

🏆 #GeForceSummer of RTX Prize Spotlight: @ASUS_ROG Swift 27” 1440P 240Hz G-SYNC Monitor
🌩️ Pair your GeForce NOW membership with this powerhouse of a monitor!
1. Tell us what game you're most looking forward to playing in August on GeForce NOW.
2. Comment #GeForceSummer
English
Azeem Shaikh retweetledi
Azeem Shaikh retweetledi
Azeem Shaikh retweetledi

🚀 Big news in healthcare AI! I'm thrilled to announce the launch of OpenMed on @huggingface, releasing 380+ state-of-the-art medical NER models for free under Apache 2.0.
And this is just the beginning! 🧵

English









