This is crazy. The hacker installed a dead-man's switch that will wipe your computer if you revoke the GitHub token they stole from you. Revoking the token is what triggers the wipe.
LibreChat v0.8.5-rc1 is out!
🏞️ Highlights:
- Admin Panel Foundation
- Context Compaction
- UI Redesign: new sidebar, refreshed prompts & tools
- Pinned Model Specs
- Performance & MCP improvements
Full changelog:
https://t.co/BUS52cTWXm
🔔 LibreChat v0.8.4 is out!
This release focused on security hardening with internal + independent pen testing, along with several bug fixes.
Strongly recommend updating.
v0.8.5-rc1 already underway with new sidebar UI and chat compaction.
📋 https://t.co/SBS0NDLz04
Software horror: litellm PyPI supply chain attack.
Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords.
LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm.
Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery - Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks.
Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages.
Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible.
@LibreChatAI just got acquired by ClickHouse!
Unified interface for LLMs, use Helicone to access any provider with top-tier observability by default.
Try it. File a bug. Run it in prod. Show us the graphs.
🎉 LibreChat is joining forces with @ClickHouseDB. Together, we're building the open-source Agentic Data Stack.
LibreChat remains 100% open source (MIT license) with the same community-first development approach.
Learn more: https://t.co/1IXihuQEkb
🔮Peek into the future of commerce!
During the keynote at @mcpsummit, we showcased the integrations of Shopify MCP servers and @LibreChatAI via MCP-UI, enabling seamless product search and purchasing capabilities.
🧵 Watch the live demo by @little_bret & @smlpth:
🚀 LibreChat v0.8.0 is here!
- Granular permissions system
- Agent marketplace
- GPT-5 & Claude Sonnet 4.5 support
- OpenRouter web search
- SharePoint integration
Thanks to our amazing community & 7 new contributors!
📜 Full changelog:
https://t.co/LKz0w33ZM7
We are launching a whole bunch of MCPs internally at @Opendoor all connected to our internal chat system built on LibreChat.
Opendoor Assistant (internal AI agent to make us work faster) also shipped yesterday.
LibreChat v0.8.0-rc3 is out now with highly anticipated features!
🔐 Granular permissions - Share prompts/agents with specific users, groups, roles, or everyone!
🏪 Agent marketplace - Discover, categorize, and share AI agents
📜 Full changelog:
https://t.co/jh4dmJJJuM
🚀 LibreChat v0.8.0-rc1 is here!
We’re moving to a weekly release cycle starting with this version. Check out what’s new and stay tuned for even faster updates!
See the v0.8.0-rc1 changelog:
👉 https://t.co/J6BnXmjm6y
Shopify runs an internal fork of librechat, and we merge most everything back. I highly recommend other companies give this project a look for their internal LLM system. It works very well for us.
AgentHouse is live now and using LibreChat, the @ClickHouseDB MCP server is extremely useful!
Try it now to see Agent capabilities (Artifacts, MCP) at work:
https://t.co/V3asiFa8eJ