Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. lol oh my god i feel **so fucking smug** right now, it's incredible.

lol oh my god i feel **so fucking smug** right now, it's incredible.

Scheduled Pinned Locked Moved Uncategorized
39 Posts 17 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • peter@thepit.socialP peter@thepit.social

    RE: https://mstdn.social/@hkrn/116284264915152671

    lol oh my god i feel **so fucking smug** right now, it's incredible. my whole body is tingling.

    tsturm@famichiki.jpT This user is from outside of this forum
    tsturm@famichiki.jpT This user is from outside of this forum
    tsturm@famichiki.jp
    wrote last edited by
    #2

    @peter Who could have seen this coming?

    flockofcats@famichiki.jpF 1 Reply Last reply
    0
    • peter@thepit.socialP peter@thepit.social

      RE: https://mstdn.social/@hkrn/116284264915152671

      lol oh my god i feel **so fucking smug** right now, it's incredible. my whole body is tingling.

      peter@thepit.socialP This user is from outside of this forum
      peter@thepit.socialP This user is from outside of this forum
      peter@thepit.social
      wrote last edited by
      #3

      i was using this package in one of my projects. i found it had a bug, and when i went to maybe try to make a contribution to the open source repository, i found it to be a huge shitpile of vibe-coded mess. methods that were thousands of lines long with **hundreds** of arguments, it was impossible, and **very** alarming. it was clear to me that no one was watching the shop, so i immediately set about removing it from my project. and now, this. 🤗

      peter@thepit.socialP 1 Reply Last reply
      0
      • tsturm@famichiki.jpT tsturm@famichiki.jp

        @peter Who could have seen this coming?

        flockofcats@famichiki.jpF This user is from outside of this forum
        flockofcats@famichiki.jpF This user is from outside of this forum
        flockofcats@famichiki.jp
        wrote last edited by
        #4

        @tsturm @peter

        It was about as hard to see coming as your bukkake squad!

        Follow for more great metaphors!

        1 Reply Last reply
        0
        • peter@thepit.socialP peter@thepit.social

          i was using this package in one of my projects. i found it had a bug, and when i went to maybe try to make a contribution to the open source repository, i found it to be a huge shitpile of vibe-coded mess. methods that were thousands of lines long with **hundreds** of arguments, it was impossible, and **very** alarming. it was clear to me that no one was watching the shop, so i immediately set about removing it from my project. and now, this. 🤗

          peter@thepit.socialP This user is from outside of this forum
          peter@thepit.socialP This user is from outside of this forum
          peter@thepit.social
          wrote last edited by
          #5

          there are **tons** of AI-related projects that use LiteLLM. it is a key part of the basic infrastructure of LLM-based development. if you use an LLM-based project, there is a good chance it uses LiteLLM.

          peter@thepit.socialP alessandro@cosocial.caA 2 Replies Last reply
          0
          • peter@thepit.socialP peter@thepit.social

            there are **tons** of AI-related projects that use LiteLLM. it is a key part of the basic infrastructure of LLM-based development. if you use an LLM-based project, there is a good chance it uses LiteLLM.

            peter@thepit.socialP This user is from outside of this forum
            peter@thepit.socialP This user is from outside of this forum
            peter@thepit.social
            wrote last edited by
            #6

            (if you're curious, it does this very useful thing of standardizing LLM APIs into a single format. makes it easy for your app to switch between Anthropic, OpenAI, Google, z.ai, etc.)

            peter@thepit.socialP 1 Reply Last reply
            0
            • peter@thepit.socialP peter@thepit.social

              (if you're curious, it does this very useful thing of standardizing LLM APIs into a single format. makes it easy for your app to switch between Anthropic, OpenAI, Google, z.ai, etc.)

              peter@thepit.socialP This user is from outside of this forum
              peter@thepit.socialP This user is from outside of this forum
              peter@thepit.social
              wrote last edited by
              #7

              this is actually a huge reason i have decided not to jump into LLM and AI agent-related development. the ecosystem is (as you would expect) run and maintained by people who are all-in on vibe coding, so a package you might like and include in your project could easily become a dangerous, unmaintainable mess within months. i don't know if people understand how brittle the whole thing is. everything is constantly, **constantly** changing.

              peter@thepit.socialP 1 Reply Last reply
              1
              0
              • peter@thepit.socialP peter@thepit.social

                this is actually a huge reason i have decided not to jump into LLM and AI agent-related development. the ecosystem is (as you would expect) run and maintained by people who are all-in on vibe coding, so a package you might like and include in your project could easily become a dangerous, unmaintainable mess within months. i don't know if people understand how brittle the whole thing is. everything is constantly, **constantly** changing.

                peter@thepit.socialP This user is from outside of this forum
                peter@thepit.socialP This user is from outside of this forum
                peter@thepit.social
                wrote last edited by
                #8

                like, it's moving **way** too fast for anyone to be able to tell if things are going to break or get injected with some malware. the whole thing is a house of cards built on top of a bomb.

                peter@thepit.socialP 1 Reply Last reply
                0
                • peter@thepit.socialP peter@thepit.social

                  like, it's moving **way** too fast for anyone to be able to tell if things are going to break or get injected with some malware. the whole thing is a house of cards built on top of a bomb.

                  peter@thepit.socialP This user is from outside of this forum
                  peter@thepit.socialP This user is from outside of this forum
                  peter@thepit.social
                  wrote last edited by
                  #9

                  oh my fucking god.

                  Link Preview Image
                  peter@thepit.socialP nan@mastodon.greenN 2 Replies Last reply
                  0
                  • peter@thepit.socialP peter@thepit.social

                    oh my fucking god.

                    Link Preview Image
                    peter@thepit.socialP This user is from outside of this forum
                    peter@thepit.socialP This user is from outside of this forum
                    peter@thepit.social
                    wrote last edited by
                    #10

                    let's see, who can i tag about this... @davidgerard will definitely want to know. @tante maybe. idk, tag your favorite cyber-security person. this might be the mother of all LLM supply chain attacks lol. @briankrebs

                    peter@thepit.socialP davidgerard@circumstances.runD 2 Replies Last reply
                    0
                    • peter@thepit.socialP peter@thepit.social

                      let's see, who can i tag about this... @davidgerard will definitely want to know. @tante maybe. idk, tag your favorite cyber-security person. this might be the mother of all LLM supply chain attacks lol. @briankrebs

                      peter@thepit.socialP This user is from outside of this forum
                      peter@thepit.socialP This user is from outside of this forum
                      peter@thepit.social
                      wrote last edited by
                      #11

                      plenty of good chatter on Hacker News about it. https://news.ycombinator.com/item?id=47501729

                      looks grim!!

                      peter@thepit.socialP gfitzp@social.glennfitzpatrick.comG wordshaper@weatherishappening.networkW 4 Replies Last reply
                      0
                      • peter@thepit.socialP peter@thepit.social

                        plenty of good chatter on Hacker News about it. https://news.ycombinator.com/item?id=47501729

                        looks grim!!

                        peter@thepit.socialP This user is from outside of this forum
                        peter@thepit.socialP This user is from outside of this forum
                        peter@thepit.social
                        wrote last edited by
                        #12

                        me right now

                        Link Preview Image
                        1 Reply Last reply
                        0
                        • peter@thepit.socialP peter@thepit.social

                          plenty of good chatter on Hacker News about it. https://news.ycombinator.com/item?id=47501729

                          looks grim!!

                          gfitzp@social.glennfitzpatrick.comG This user is from outside of this forum
                          gfitzp@social.glennfitzpatrick.comG This user is from outside of this forum
                          gfitzp@social.glennfitzpatrick.com
                          wrote last edited by
                          #13

                          @peter https://arstechnica.com/security/2026/03/self-propagating-malware-poisons-open-source-software-and-wipes-iran-based-machines/

                          peter@thepit.socialP 1 Reply Last reply
                          0
                          • gfitzp@social.glennfitzpatrick.comG gfitzp@social.glennfitzpatrick.com

                            @peter https://arstechnica.com/security/2026/03/self-propagating-malware-poisons-open-source-software-and-wipes-iran-based-machines/

                            peter@thepit.socialP This user is from outside of this forum
                            peter@thepit.socialP This user is from outside of this forum
                            peter@thepit.social
                            wrote last edited by
                            #14

                            @gfitzp oh yeah, it's those guys!

                            peter@thepit.socialP 1 Reply Last reply
                            0
                            • peter@thepit.socialP peter@thepit.social

                              @gfitzp oh yeah, it's those guys!

                              peter@thepit.socialP This user is from outside of this forum
                              peter@thepit.socialP This user is from outside of this forum
                              peter@thepit.social
                              wrote last edited by
                              #15

                              @gfitzp oh nooooo

                              Link Preview Image
                              gfitzp@social.glennfitzpatrick.comG 1 Reply Last reply
                              0
                              • peter@thepit.socialP peter@thepit.social

                                plenty of good chatter on Hacker News about it. https://news.ycombinator.com/item?id=47501729

                                looks grim!!

                                peter@thepit.socialP This user is from outside of this forum
                                peter@thepit.socialP This user is from outside of this forum
                                peter@thepit.social
                                wrote last edited by
                                #16

                                based on some commits in the repo, seems like it was these guys: https://arstechnica.com/security/2026/03/self-propagating-malware-poisons-open-source-software-and-wipes-iran-based-machines/

                                mkristensson@thepit.socialM peter@thepit.socialP 2 Replies Last reply
                                0
                                • peter@thepit.socialP peter@thepit.social

                                  @gfitzp oh nooooo

                                  Link Preview Image
                                  gfitzp@social.glennfitzpatrick.comG This user is from outside of this forum
                                  gfitzp@social.glennfitzpatrick.comG This user is from outside of this forum
                                  gfitzp@social.glennfitzpatrick.com
                                  wrote last edited by
                                  #17

                                  @peter Yup, I was like "didn't I just read about these guys like an hour ago??"

                                  1 Reply Last reply
                                  0
                                  • peter@thepit.socialP peter@thepit.social

                                    based on some commits in the repo, seems like it was these guys: https://arstechnica.com/security/2026/03/self-propagating-malware-poisons-open-source-software-and-wipes-iran-based-machines/

                                    mkristensson@thepit.socialM This user is from outside of this forum
                                    mkristensson@thepit.socialM This user is from outside of this forum
                                    mkristensson@thepit.social
                                    wrote last edited by
                                    #18

                                    @peter and @dangoodin sometimes hangs out here

                                    1 Reply Last reply
                                    0
                                    • peter@thepit.socialP peter@thepit.social

                                      based on some commits in the repo, seems like it was these guys: https://arstechnica.com/security/2026/03/self-propagating-malware-poisons-open-source-software-and-wipes-iran-based-machines/

                                      peter@thepit.socialP This user is from outside of this forum
                                      peter@thepit.socialP This user is from outside of this forum
                                      peter@thepit.social
                                      wrote last edited by
                                      #19

                                      picking through the various bits and pieces of this story, i kind of think what really happened is the dev accounts got pwned, and then the attackers were able to push a bad version to PyPi and people pip installed it from there. so as far as a "supply chain" attack, LiteLLM is the part of the supply chain that got attacked, it's not like they accidentally vibe-coded something malicious into their project.

                                      peter@thepit.socialP 1 Reply Last reply
                                      0
                                      • peter@thepit.socialP peter@thepit.social

                                        RE: https://mstdn.social/@hkrn/116284264915152671

                                        lol oh my god i feel **so fucking smug** right now, it's incredible. my whole body is tingling.

                                        jongary@macaw.socialJ This user is from outside of this forum
                                        jongary@macaw.socialJ This user is from outside of this forum
                                        jongary@macaw.social
                                        wrote last edited by
                                        #20

                                        @peter it isn’t even necessary to compromise repos. If a malicious actor posts enough malicious code that gets mingled with the LLM training data, some poor souls will start vibe-coding malicious code directly into their own products.

                                        peter@thepit.socialP 1 Reply Last reply
                                        0
                                        • peter@thepit.socialP peter@thepit.social

                                          picking through the various bits and pieces of this story, i kind of think what really happened is the dev accounts got pwned, and then the attackers were able to push a bad version to PyPi and people pip installed it from there. so as far as a "supply chain" attack, LiteLLM is the part of the supply chain that got attacked, it's not like they accidentally vibe-coded something malicious into their project.

                                          peter@thepit.socialP This user is from outside of this forum
                                          peter@thepit.socialP This user is from outside of this forum
                                          peter@thepit.social
                                          wrote last edited by
                                          #21

                                          but this still goes back to what i was saying: this AI ecosystem is developing **way** too fast and without the kind of maturity that is naturally required when you have lots of people working on a thing. so with berri.ai, you had ~2 guys in their 20s building this thing at break-neck speed that became the linchpin to waaaaay too much of the "AI" ecosystem and now look what's happened.

                                          1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups