@karpathy
Some links 2,112 total packages depend on litellm (https://t.co/T8xWdrBp9g), 1,403 of them directly. Among these are e.g. DSPy, Open Interpreter, PraisonAI, MLflow, langchain-litellm. Primary Sources 1. Original disclosure (GitHub issue): https://t.co/w0j29cVvdq β the detailed technical writeup of the malicious payload, what it steals, how it works 2. BerriAI's official tracking issue: https://t.co/Jc4iIW7Qmr β the team's response and status updates 3. FutureSearch blog (the people who found it): https://t.co/SaX6ClxW8S β how a fork bomb bug in the malware crashed their machine and led to discovery 4. ramimac's full TeamPCP timeline: https://t.co/nfVesVbrnp β the broader campaign: Trivy β Checkmarx β litellm, with exact timestamps and IOCs 5. PyPA advisory: https://t.co/b7mJsYQkB3 β the official PYSEC-2026-2 Analysis & Discussion 6. Hacker News thread (main): https://t.co/t3BPEMVtk5 β includes direct responses from Krrish (litellm maintainer), best real-time discussion 7. Hacker News thread (early): https://t.co/5qxHxf3pvx β the first HN post 8. GitGuardian writeup: https://t.co/uaCmm1TqHO β good analysis of how leaked CI/CD secrets enabled the whole chain 9. Wiz blog on the broader campaign: https://t.co/CsdOgm9Ios β TeamPCP's attack on Checkmarx/KICS, same actor Downstream Impact 10. DSPy issue: https://t.co/sbgN2AWWlP 11. MLflow emergency pin PR: https://t.co/5gQbxU2Iou 12. DSPy emergency pin PR: https://t.co/AYKgJWdkkz Quick Summary for Your Post - 46-minute window of exposure on PyPI (10:39β11:25 UTC, Mar 24) - ~1,400 packages directly depend on litellm, all with open-ended version ranges - Caught because the malware had a bug (fork bomb) that crashed the discoverer's machine - Root cause: Trivy (a vulnerability scanner) was itself compromised, which leaked litellm's PyPI publish token - Attacker (TeamPCP) spammed the GitHub issue with hundreds of bot comments to bury the discussion