Hackernews posts about PyPI
PyPI is the Python Package Index, a repository of open-source software packages for the Python programming language.
- Telnyx package compromised on PyPI (telnyx.com)
- Telnyx package compromised on PyPI (www.aikido.dev)
- LiteLLM PyPI has been compromised an hour ago, do not update (futuresearch.ai)
- Supply Chain Attack in litellm 1.82.8 on PyPI (futuresearch.ai)
- Popular LiteLLM PyPI package backdoored to steal credentials, auth tokens (www.bleepingcomputer.com)
- TeamPCP strikes again – telnyx popular PyPI library compromised (research.jfrog.com)
- Litellm PyPI supply chain attack (twitter.com)
- Compromised telnyx on PyPI (safedep.io)
- PyPI and GitHub package stats combined (pypi.kopdog.com)
- Litellm 1.82.7 and 1.82.8 on PyPI are compromised (old.reddit.com)
- SBOM Adoption on PyPI Is at 1.58%. We Can Do Better (sbomify.com)
- My minute-by-minute response to the LiteLLM malware attack (futuresearch.ai)