LiteLLM Python package compromised by supply-chain attack
An Internet who works for BerriAI (business model: 'Uber for API calls') discovers the Python library he uses to automate shilling for six strangers per day has been automatically stealing everyone's credentials, after the package repository PyPI (business model: 'Uber for malware distribution') dutifully served the backdoored version to all comers. Hackernews, literally all of whom are security architects who have solved the trusting-trust problem in their heads, immediately propose building a towering edifice of nested sandboxes, egress filters, and mandatory LLM code reviewers, while other Hackernews frantically share links to seven competing libraries (business model: 'Uber for the next supply-chain attack'). Meanwhile, the empty suit maintainer (business model: 'Uber for credential surrender') explains the compromise originated from a compromised security scanner, thus completing the elegant ouroboros of modern development, where the only thing being served to six strangers is their own financial ruin.