Phiz

11.4K posts

Phiz banner
Phiz

Phiz

@PhizComms

Professional Communicator - CEO, PMCS - Digital Asset Management/GR/PR $BTC

Southern US เข้าร่วม Mart 2022
1.6K กำลังติดตาม4.6K ผู้ติดตาม
Phiz
Phiz@PhizComms·
@Dios_0ficial @grok a friend wants to know the name of the girl in the red dress. Can you help her out?
English
1
0
0
1.8K
Dios
Dios@Dios_0ficial·
Ahora entenderás por qué los Óscares están sobrevalorados.
Español
439
707
21.4K
3.7M
Aakash Gupta
Aakash Gupta@aakashgupta·
Someone just poisoned the Python package that manages AI API keys for NASA, Netflix, Stripe, and NVIDIA.. 97 million downloads a month.. and a simple pip install was enough to steal everything on your machine. The attacker picked the one package whose entire job is holding every AI credential in the organization in one place. OpenAI keys, Anthropic keys, Google keys, Amazon keys… all routed through one proxy. All compromised at once. The poisoned version was published straight to PyPI.. no code on GitHub.. no release tag.. no review. Just a file that Python runs automatically on startup. You didn’t need to import it. You didn’t need to call it. The malware fired the second the package existed on your machine. The attacker vibe coded it… the malware was so sloppy it crashed computers.. used so much RAM a developer noticed their machine dying and investigated. They found LiteLLM had been pulled in through a Cursor MCP plugin they didn’t even know they had. That crash is the only reason thousands of companies aren’t fully exfiltrated right now. If the code had been cleaner nobody notices for weeks. Maybe months. The attack chain is the part that gets worse every sentence. TeamPCP compromised Trivy first. A security scanning tool. On March 19. LiteLLM used Trivy in its own CI pipeline… so the credentials stolen from the SECURITY product were used to hijack the AI product that holds all your other credentials. Then they hit GitHub Actions. Then Docker Hub. Then npm. Then Open VSX. Five package ecosystems in two weeks. Each breach giving them the credentials to unlock the next one. The payload was three stages.. harvest every SSH key, cloud token, Kubernetes secret, crypto wallet, and .env file on the machine.. deploy privileged containers across every node in the cluster.. install a persistent backdoor waiting for new instructions. TeamPCP posted on Telegram after: “Many of your favourite security tools and open-source projects will be targeted in the months to come.. stay tuned.” Every AI agent, copilot, and internal tool your company shipped this year runs on hundreds of packages exactly like this one… nobody chose to install LiteLLM on that developer’s machine. It came in as a dependency of a dependency of a plugin. One compromised maintainer account turned the entire trust chain into a credential harvesting operation across thousands of production environments in hours. The companies deploying AI the fastest right now have the least visibility into what’s underneath it.
Andrej Karpathy@karpathy

Software horror: litellm PyPI supply chain attack. Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords. LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm. Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery - Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks. Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages. Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible.

English
297
2.2K
11K
2.7M
定
@de3dsoul·
That moment in a game when you know you were about to play a masterpiece
English
192
416
12.8K
1.7M
CLEAN CAR CLUB
CLEAN CAR CLUB@TheCleanCarClub·
The first thing to in a hotel
English
2.8K
480
4.6K
3.2M
Phiz
Phiz@PhizComms·
@mattvanswol Yeah… the worst part about coming home is… coming home.
English
0
0
0
15
Matt Van Swol
Matt Van Swol@mattvanswol·
🚨HOLY CRAP!!! The Houston TSA line has now stretched to a mind-blowing 150 minute-wait-time and has snaked around the airport, down an escalator and into BAGGAGE CLAIM!!! THIS IS INSANE!!!!
English
3.7K
6.6K
22.8K
6.1M
Phiz
Phiz@PhizComms·
What happens when you sign up for a Bonnie Blue gangbang and you aren’t a man who finishes quickly? Do they tell you that your time is up? Does she bring a friend that you can finish with or do you have to take care of it yourself? Asking for a friend.
English
0
0
0
84
Grave Wolf Sif
Grave Wolf Sif@GraveWolfSif·
@40kARTdotcom It is genuinely terrifying that there could be 10 men that'd want to participate, let alone thousands. What sort of demented, degenerate, dumbshit man would participate in the sloppiest of seconds? GTFOH.
English
1
0
3
228
Warhammer 40K Art
Warhammer 40K Art@40kARTdotcom·
Is she trying to summon Slannesh?
Warhammer 40K Art tweet media
English
629
71
1.6K
183.6K
Phiz
Phiz@PhizComms·
The Jared Leto hate is unjustified.
English
0
0
0
25
Phiz
Phiz@PhizComms·
@ClownWorld Looks like a good way to waste $15.
English
0
0
0
42
Clown World ™ 🤡
Clown World ™ 🤡@ClownWorld·
Man's decided the cops aren’t doing enough so now he's launching desserts at speeding cars 😭
English
2.5K
2.8K
33.4K
5M
Phiz
Phiz@PhizComms·
@FearedBuck …but what did he do to deserve it?
English
0
0
0
15
FearBuck
FearBuck@FearedBuck·
ABC has canceled The Bachelorette after their lead was seen in a leaked footage physically attacking her ex-boyfriend and throwing metal chairs at him while her child was present and reportedly the child was struck during the altercation.
English
5.1K
10.2K
132K
18.9M
Phiz
Phiz@PhizComms·
This self censoring sh*t on YouTube is out of control. I can barely get through a video without hearing something stupid like “unalived” and SA. It’s like it all have to be approved by the thought police before it gets to me. I could have sworn I checked the “over 21” box.
English
0
0
1
36
Phiz
Phiz@PhizComms·
@AdamDoesMovies_ Adam, there are 5 categories of drink: Water Milk Juice Beer and Coke There is no “pop”.
English
0
0
0
32
Phiz
Phiz@PhizComms·
@Nerdrotics Thanks for the reply! You’re a legend at my house Gary!
English
0
0
0
9
Nerdrotic
Nerdrotic@Nerdrotics·
@PhizComms Well, I sit corrected. A billion dollars for Supergirl😉
English
3
1
8
443
Phiz
Phiz@PhizComms·
@Nerdrotics Dude! Claudia Sarne was the lead singer for 12 Rounds, who Trent Reznor discovered. She's married to Atticus Ross who's Trent's partner in NIN right now. This is exciting news! Check out their best song: youtube.com/watch?v=2ZPB-B…
YouTube video
YouTube
English
1
1
4
607
Phiz
Phiz@PhizComms·
@Nerdrotics lol. Didn’t say the movie would be GOOD!
English
0
0
1
18
Phiz
Phiz@PhizComms·
@Nerdrotics Dude! Claudia Sarne is/was the lead singer for 12 Rounds, who Trent Reznor discovered. She's married to Atticus Ross, who is currently 1/2 of NIN. This is exciting news! I cant wait to hear this. Check out their biggest song. youtube.com/watch?v=2ZPB-B…
YouTube video
YouTube
English
0
0
0
17
Nerdrotic
Nerdrotic@Nerdrotics·
🚨NEW VIDEO CLIP SUPERGIRL IS IN BIG TROUBLE – James Gunn’s DCU Problems Run Deeper Than You Think👇 🔥youtube.com/watch?v=1EQc0K…🔥
YouTube video
YouTube
Nerdrotic tweet media
English
23
29
300
13.6K
Phiz
Phiz@PhizComms·
@MarinasHammer I want to hear Werner Herzog read this aloud.
English
0
0
0
75
SLC Fatigue
SLC Fatigue@MarinasHammer·
Los Angeles is so bad that you will get stabbed charging your car at the city library by a homeless man, and when an ambulance comes to save you, ANOTHER homeless man steals the ambulance while they’re tending to you at the scene leaving you no way to get to the hospital, and you die. Sounds like South Africa…
KTLA@KTLA

The family of a man who was stabbed to death by a homeless man while he was charging his electric car outside the Downey City library has filed a claim against the city seeking $40 million in damages. Details: ktla.com/news/local-new…

English
1.2K
6.9K
37.6K
54.8M
Best Clips
Best Clips@best_clips__·
Whoever cast her, evil asf
English
354
845
16.3K
5M