LiteLLM PyPI has been compromised an hour ago, do not update

https://futuresearch.ai/blog/litellm-pypi-supply-chain-attack/

Comments

darkteflonMar 24, 2026, 7:50 PM
We recently switched to pnpm, in part to guard against supply chain attacks (https://pnpm.io/supply-chain-security).

Reading this got me wondering whether uv has something similar, and indeed it does appear to (https://docs.astral.sh/uv/reference/settings/#exclude-newer)

nateb2022Mar 25, 2026, 8:57 PM
Wherever practical, I also recommend using devcontainers, so that in addition to breaking supply chain security, large-scale damage would require an unpatched sandbox exploit too.
rgambeeMar 24, 2026, 12:19 PM
It's also been reported to their GitHub: https://github.com/BerriAI/litellm/issues/24512
Bullhorn9268Mar 24, 2026, 12:20 PM
yeah, updated in the post
parad0x0nMar 24, 2026, 12:14 PM
Thank you!
MooshuxMar 25, 2026, 3:17 PM
[dead]