🚨 WOAH: TRUMP JUST SCRAPPED HIS CAMP DAVID MEETING AND ORDERED HIS ENTIRE CABINET BACK TO THE WHITE HOUSE 🚨
Rubio says a DEAL is “ONE WORD AWAY”… 90% COMPLETE 🔥
Trump is holding the HAMMER… and he just PINNED THE ENTIRE ARAB WORLD AGAINST IRAN 🔥 🔥
The Arabs are STUNNED by the DEAL 💣
In Japanese, “tsundoku” means collecting books and letting them pile up - not for neglect, but for the joy of knowing they're there, full of untold stories.
📍DAIKANYAMA T-SITE, Tokyo
LiteLLM HAS BEEN COMPROMISED, DO NOT UPDATE. We just discovered that LiteLLM pypi release 1.82.8. It has been compromised, it contains litellm_init.pth with base64 encoded instructions to send all the credentials it can find to remote server + self-replicate. link below
Software horror: litellm PyPI supply chain attack.
Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords.
LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm.
Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery - Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks.
Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages.
Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible.
🚨 Andrej Karpathy just explained the scariest thing happening in software right now..
someone poisoned a Python package that gets 97 million downloads a month.. and a simple pip install was enough to steal everything on your machine..
SSH keys.. AWS credentials.. crypto wallets.. database passwords.. git credentials.. shell history.. SSL private keys.. everything..
and here's the part that should terrify every developer alive..
the attack was only discovered because the attacker wrote sloppy code.. the malware used so much RAM that it crashed someone's computer.. if the attacker had been better at coding.. nobody would have noticed for weeks..
one developer.. using Cursor with an MCP plugin.. had litellm pulled in as a dependency they didn't even know about.. their machine crashed.. and that crash saved thousands of companies from getting their entire infrastructure stolen..
Karpathy's take is the real wake up call.. every time you install any package you're trusting every single dependency in its tree.. and any one of them could be poisoned..
vibe coding saved us this time.. the attacker vibe coded the attack and it was too sloppy to work quietly.. next time they won't make that mistake.
10 years in design taught me:
always give.
I'm giving it all away today:
- Claude smart prompts
- semantic tokens bible
- figma template
- platforms for references
- keywords for search
- txt & video tutorials
and more
Save the article. Come back when your need it 👇
This is how the daycare fraud works:
- “You watch my kid, I’ll watch yours”
- Enroll these kids into “daycares”
- Collect money from the government
- You and your family then get to live off government subsidies
California has over 35,000+ licensed daycare facilities
Anthropic is guilty of stealing training data at massive scale and has had to pay multi-billion dollar settlements for their theft. This is just a fact.
BREAKING: 21 children have been discovered in a Southern California home, all conceived via surrogacy.
The discovery came after a local hospital reported suspected child neglect when a 2-month-old suffered severe head trauma, appearing to have been shaken, dropped, or subjected to a traumatic incident. When Arcadia police investigated, they found 21 children inside the home.
The couple, Silvia Zhang and Guojun Xuan, are Chinese-born residents.
These children were not welcomed into a loving family with a mother and father. They were intentionally created, separated from their biological mothers, and treated as products to satisfy adult desires.
Surrogacy is not a loving form of adoption — it enables the commodification and trafficking of vulnerable children.
Leading surrogacy expert Katy Faust joins me in the studio to break this down further in E294 of The Lila Rose Show.
Watch.