fhools⚡️🦀
15.7K posts

fhools⚡️🦀
@fhools
code aficionado. fan of Bitcoin. owns 1 chair and 1 rubber knife. solana tech is pretty cool too. llm enjoyer. i own pdai, fight me.
เข้าร่วม Nisan 2012
6.2K กำลังติดตาม1.3K ผู้ติดตาม
fhools⚡️🦀 รีทวีตแล้ว
fhools⚡️🦀 รีทวีตแล้ว

"Your job won't be taken by AI, it will be taken by Meek Mill using AI"
- Jensen Huang
MeekMill@MeekMill
I need a GitHub too! Is it like that or nah?
English
fhools⚡️🦀 รีทวีตแล้ว

Software horror: litellm PyPI supply chain attack.
Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords.
LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm.
Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery - Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks.
Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages.
Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible.
Daniel Hnyk@hnykda
LiteLLM HAS BEEN COMPROMISED, DO NOT UPDATE. We just discovered that LiteLLM pypi release 1.82.8. It has been compromised, it contains litellm_init.pth with base64 encoded instructions to send all the credentials it can find to remote server + self-replicate. link below
English

Meek Mill reportedly failed to git pull his latest changes before pushing, causing a devastating merge conflict.


MeekMill@MeekMill
I need a GitHub too! Is it like that or nah?
English

@PeakThinkers_ That's actually common. Homework is hard sometimes. Bezos is a quitter.
English

Jeff Bezos on the exact moment he realized he would never be a great physicist:
"I wanted to be a theoretical physicist. I went to Princeton. I was a really good student, I got A-pluses on almost everything. I was in the honors physics track, which starts with 100 students and by quantum mechanics it's down to 30."
Then came the homework problem:
"I can't solve this partial differential equation. It's really, really hard. I've been studying with my roommate Joe, who was also really good at math. The two of us worked on this one problem for three hours and got nowhere."
They decided to visit Yasantha, the smartest guy at Princeton:
"He was Sri Lankan. In the Facebook, which was an actual paper book at that time, his name was three lines long. I guess in Sri Lanka when you do something good for the king, they give you an extra syllable on your name. The most humble, wonderful guy."
Jeff continues:
"We show him the problem. He stares at it for a while and says, 'Cosine.' I'm like, 'What do you mean?' He says, 'That's the answer.' I said, 'That's the answer?' He said, 'Yeah, let me show you.' He sits us down, writes out three pages of detailed algebra, everything crosses out, and the answer is cosine."
Jeff asked if he solved it in his head:
"He said, 'No, that would be impossible. Three years ago I solved a very similar problem and I was able to map this problem onto that one. Then it was immediately obvious the answer was cosine.'"
Jeff reflects:
"That was an important moment for me. Because that was the very moment I realized I was never going to be a great theoretical physicist."
English

@cqcqcqdx My immigrant mom got me a Atari XEGS instead of a NES because that's what moms do. I recall it had a manual with BASIC code, at the time I had no idea what the hell all this code listing was about. I wish I could go back and look at that code now that I'm a programmer.
English

@MindDynamo I be like this because of cortisolmaxx spiking. I listen to my body.
English

@VibraFinance What do you mean? Bonding with PRVX is one of the most bullish signs for PDAI.
English

I fell for the $PDAI scam. If you are following people still shilling it, wake up.
Bonding it with $PRVX allows the goal post to be moved 50 more times. We wanted it to be true so bad…
The faster we realize they were bad actors all along, the quicker we move forward #Pulsechain
English
fhools⚡️🦀 รีทวีตแล้ว
fhools⚡️🦀 รีทวีตแล้ว

@StopUnlifingUs @rolandphelan @HustleBitch_ I'll have to pay more attention to the moon from now on. Aliens are up to something.
English

@rolandphelan @fhools @HustleBitch_ Pretty sure this is a mandela effect. Or timeline shifting thing. Yes, I believe someone is altering timelines.
Half of use come from a timeline where the moon didn't do this and the other half did. Which leaves us fighting each other.
Only explanation I have left. 😀
English

🚨 SOMETHING STRANGE IS HAPPENING TO THE MOON — AND THEY DON’T WANT YOU TO NOTICE
A woman gets on camera and says this isn’t a one-time thing. She saw it last month, the moon looked completely off, like the orientation made no sense, but she brushed it off and kept it moving.
Now it’s happening again.
Same exact look.
So this time she actually checks, pulls up NASA charts for her exact location and shows what the moon is supposed to look like… and what she’s seeing doesn’t match it, not even close.
The charts show it side to side, but what everyone actually saw was a flipped moon, straight up upside down, like something changed and everyone’s acting like it didn’t.
Then she calls people across the country to verify it, and they come back saying the same thing. It looks upside down to them too, which is where this stops being “just her” and starts feeling like the same exact thing showing up in multiple places at the same time.
And it’s not just her, people all over social media are saying the same thing: "Something isn't right."
And this is where it stops making any sense.
She says if the moon is a crescent, you’re only supposed to see the lit part… so why can she still see the entire outline of it, faint but clearly there, like the shadow isn’t even doing what it’s supposed to do?
And she’s already calling it out before anyone can spin it: don’t say it’s lighting, don’t say it’s angle, don’t say it’s photoshopped, because she checked the charts, showed the receipts, and had other people confirm it.
So now you’ve got the same “flip,” the same upside down moon, same visibility issue, second month in a row, multiple locations… and it still doesn’t match what we’re being shown.
She ignored it once.
Now it’s back again.
So what exactly are we looking at… and why does it feel like we’re not supposed to question it?
English
fhools⚡️🦀 รีทวีตแล้ว

@PulseProveX I DCA here and there into pHEX and eHEX because its so cheap and to abandon your first coin is a sin.
English

@AngelicaOung Quit, or stick with vapes. Zyn pouches made my gums recede.
English

Confession: I'm a dumb bitch
What happened was I read on twitter dot com that nicotine when not smoked is actually an amazing nootropic that helps your concentration with no negative side effect.
...aaaaand after avoiding smoking for my entire adult life I'm now addicted to zyns.
The don't even feel good anymore. I'm just popping them for no reason until I feel vaguely nauseous.
English
fhools⚡️🦀 รีทวีตแล้ว












