FutureSearch
3 mentions across all digests
FutureSearch is a company whose researcher Callum McMahon discovered credential-stealing malware embedded in a LiteLLM PyPI supply chain attack after it crashed his machine.
My minute-by-minute response to the LiteLLM malware attack
Forensic analysis of suspected LiteLLM supply chain attack reveals orphaned Python processes and base64-encoded payloads were actually normal Claude Code execution behavior, not malware.
LiteLLM Compromised by Credential Stealer
PyPI supply chain attack compromises LiteLLM versions 1.82.7–1.82.8 with malicious `.pth` file harvesting SSH keys, cloud credentials, and crypto wallets on every Python startup.
Delve did the security compliance on LiteLLM, an AI project hit by malware
A supply chain attack injected credential-stealing malware into LiteLLM, a dependency downloaded 3.4M times daily by AI developers, exposing gaps in SOC 2 compliance auditing for AI infrastructure tools.