GitGuardian says the TeamPCP campaign poisoned two LiteLLM releases on PyPI to harvest SSH keys, cloud credentials and API tokens. Detection is the cheap part of this job.
Publishers:blog.gitguardian.com
Reality
- Evidence52
- Adoption27
- Hype gap+24
- Incentives78
- Confidence46
Hudson Rock's analysis of the exfiltration archive ties 118,829 CI runner dumps to 2,488 organizations. The dumps carrying no identifying metadata are the harder half.
Publishers:blog.gitguardian.com
Reality
- Evidence56
- Adoption71
The vendor reports 10-plus CVEs and up to 200,000 exposed instances, and says Anthropic declined to change the protocol, describing the behaviour as expected.
Publishers:ox.security
Reality
- Evidence32
- Adoption34
build1 distinct publisher A 9B MIT-licensed coding model that reportedly matches a 31B rival on SWE-Bench Verified is still unusable as a Claude Code backend, because the runtime never turns its tool-call XML into a file write.
Publishers:dev.to
Reality
- Evidence44
- Adoption18
Check Point Research says a nonce bug in every public VECT build leaves files above 131,072 bytes unrecoverable, by the attacker as well. That turns extortion into destruction.
Publishers:research.checkpoint.com
Reality
- Evidence74
- Adoption22
build1 distinct publisher VMR's maintainer publishes routing overhead and cache-hit numbers to argue that unattended coding agents need byte-faithful pass-through and session affinity. Everything else is complexity.
Publishers:dev.to
Reality
- Evidence34
- Adoption
- Insufficient
- Hype gap
build1 distinct publisher A 2.5-year retrospective spanning more than 250 engineering teams credits a LiteLLM-based API proxy, stood up in January 2024, for metering adoption and forcing client upgrades.
Publishers:engineering.zalando.com
Reality
- Evidence46
- Adoption64
build1 distinct publisher A backdoored LiteLLM build was downloaded about 47,000 times in a three-hour window. Most agent incidents never get a CVE, so your scanner dashboard is not the control you think it is.
Publishers:dev.to
Reality
- Evidence30
- Adoption46
SOCRadar's record-level data puts 95 percent of identified victims before the poisoned LiteLLM packages ever hit PyPI. Anyone who rotated only what LiteLLM touched is still exposed.
Publishers:securityweek.com
Reality
- Evidence52
- Adoption68