I am confused; did you ever actually email anyone about the vuln? The AI suggests emailing security emails multiple times, but as I'm reading the timeline, none of the points seem to suggest this was ever done, only that a blog post was made, shared on Reddit, and then indirectly, the relevant parties took action.
I'm hoping this just isn't on the timeline.
The first line of the post is:
> I'm the engineer who got PyPI to quarantine litellm.
In guessing they used a tool other than Claude Code to serve the email.