logoalt Hacker News

GrayShadeyesterday at 3:18 PM1 replyview on HN

1.82.7 doesn't have litellm_init.pth in the archive. You can download them from pypi to check.

EDIT: no, it's compromised, see proxy/proxy_server.py.


Replies

cpburns2009yesterday at 3:20 PM

1.82.7 has the payload in `litellm/proxy/proxy_server.py` which executes on import.