Elektrine lite

← Feed

@dangoodin@infosec.exchange

Post #768807

2026-03-24 16:49 UTC

Wow, TeamPCP is hacking open-source developers faster than we can report on them. The latest (that I'm aware of, anyway) is LiteLLM. They worked with Trivy but didn't bother to change their credentials after Trivy was hacked, despite an ample amount of advice to do so. Folks, if any of you used LiteLLM, now is the time to change your credentials, in an atomic way. Now, as in immediately. https://news.ycombinator.com/item?id=47501729

Replies (3)

  • @dangoodin@infosec.exchange 2026-03-24 16:49

    For context, please see: https://arstechnica.com/security/2026/03/self-propagating-malware-poisons-open-source-software-and-wipes-iran-based-machines/

    Open ##1253048

  • @dubbel@mstdn.io 2026-03-24 17:18

    @dangoodin I think it's "in an atomic way", meaning "rotate all credentials in one operation", so that attackers cannot use the still working creds to observe the new ones while they are being updated one after another. And I agree, it's absolutely crazy right now.

    Open ##1253050

  • @SsamanMardi@gruene.social 2026-03-24 20:05

    @dangoodin does only affect the pip install, right?

    Open ##1253052