Slowmist Chief Information Security Officer 23pds posted on Twitter stating that the Python AI gateway library LiteLLM, which has monthly downloads of up to 97 million, has been subjected to a PyPI supply chain attack. Attackers can steal sensitive information on users' devices through the pip install litellm command. The sensitive data that can be stolen includes: SSH keys, cloud service credentials (AWS / GCP / Azure), Kubernetes configuration files, Git credentials, API keys in environment variables, Shell history, cryptocurrency wallet information, and database passwords, among others.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin