熊貓隨口說
09:52 · 2026年3月25日 · 週三
https://fixupx.com/karpathy/status/2036487306585268612?s=46&t=1LAyoawP6LK1AbrwCvLGqQ
FixupX
Andrej Karpathy (@karpathy)
Software horror: litellm PyPI supply chain attack.
Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD…
Home
Powered by
BroadcastChannel
&
Sepia