Vibecodefags absolutely BTFO.Vibecoded LLM Gateway provider had malicious credential stealing script hidden in the pypi package.https://github.com/BerriAI/litellm/issues/24518https://github.com/BerriAI/litellm/issues/24521
>>108445249what are some other creative ways to ruin vibecoder's lives? asking for a friend.
the current state of ""superior"" open source, you might as well install Windows XP and run Fast&Furious.avi.exe
This whole project is a shambles, hundreds of files all thousands of lines long. It's written by a couple of kids fresh out of college. The actual exploit is quite simple too. It's a script that runs every time you open a Python interpreter and sends all the credentials and keys from your machine to a remote service.
>>108445271
>7k branches>1.1k pull requests>1k open issues>32k commitswhat a mess.
>>108445434And it's all python. It's far too high traffic for me to touch it, must be easy to sneak stuff in there. Though to be fair it just looks the like the issue was simple credentials theft which allowed the attacker to push a compromised package to PyPi.
>>108445249The docker images apparently weren't affected thankfully.
>>108445249Imagine using this shit when you can just make http requests.
>>108445249>>108445258
>>108445249open source bros? our response?
>>108445629>horse analogy
I wonder how many companies got fucked by this, I know it's used by a lot.
>>108445629>crypto baggies using the same garbage tier analogies to AI shitwareya, that's how I know it's a shitty fad.
>>108445249Is that something the AI did?
I have no credentials to steal
>>108445629gm sar
>>108446502No, but the project is run by amateurs. These supply chain attacks are something to be wary off with OSS. It was particularly effective in this case due to it being such a high traffic bloated library. Good job they caught it earlyish but I bet there are plenty of people using dependabot or similar that don't realise they've had their creds leaked.
>>108445629>maan, i posted it again
>>108445249Is this really only used by vibecoders? I think it's probably used by all those companies whose names are in LiteLLM's site... I mean they're using agents but not all of them are retards, I suppose. I mean, Adobe? They gotta have some good ones there
>>108445629cars don't have a horsecock