Callum McMahon
2 mentions across all digests
Callum McMahon is a researcher at FutureSearch who discovered the LiteLLM supply chain attack in version 1.82.8 after malware crashed his machine, using Claude in an isolated Docker container to confirm the malicious payload.
My minute-by-minute response to the LiteLLM malware attack
LiteLLM 1.82.8 was poisoned on PyPI with a malicious `.pth` file executing base64 payloads on install—a supply chain attack on a foundational LLM routing library affecting the entire AI ecosystem.
Delve did the security compliance on LiteLLM, an AI project hit by malware
A supply chain attack injected credential-stealing malware into LiteLLM, a dependency downloaded 3.4M times daily by AI developers, exposing gaps in SOC 2 compliance auditing for AI infrastructure tools.