Y
Hacker News
new
|
ask
|
show
|
jobs
by
outside2344
84 days ago
Is it just in 1.82.8 or are previous versions impacted?
1 comments
Imustaskforhelp
84 days ago
1.82.7 is also impacted if I remember correctly.
link
GrayShade
84 days ago
1.82.7 doesn't have litellm_init.pth in the archive. You can download them from pypi to check.
EDIT: no, it's compromised, see proxy/proxy_server.py.
link
cpburns2009
84 days ago
1.82.7 has the payload in `litellm/proxy/proxy_server.py` which executes on import.
link