Hacker News new | ask | show | jobs
by mrkeen 125 days ago
> Why is the LiteLLM incident on there? The linked article for that one is a 404.

-> [Endor Labs] https://www.endorlabs.com/learn/teampcp-isnt-done

-> On March 24, 2026, Endor Labs identified that litellm versions 1.82.7 and 1.82.8 on PyPI contain malicious code not present in the upstream GitHub repository. litellm is a widely used open source library with over 95 million month downloads. It lets developers route requests across LLM providers through a single API.

2 comments

How does that relate to vibe coding?
That doesn't answer how stolen credentials are related to AI-assisted coding.