Voices
Karpathy: LiteLLM Supply Chain Attack Is 'Scariest Thing in Modern Software' — Cascading Dependency Risk Threatens Entire AI Ecosystem
Andrej Karpathy posted a viral warning (13,382 likes, 2.9M views) calling the LiteLLM PyPI supply chain attack 'software horror,' noting that a simple pip install was enough to exfiltrate SSH keys, cloud credentials, crypto wallets, and CI/CD secrets. He emphasized the cascading nature: over 2,000 commonly used AI tools including DSPy, MLflow, and Open Interpreter depend on LiteLLM, and the attack was only discovered because the attacker's own code had a bug that crashed a developer's machine when an MCP plugin in Cursor pulled LiteLLM as a transitive dependency.
Source
↳ Follow the thread