Boosted by keul@fosstodon.org ("Luca Fabbri"):
Khrys@mamot.fr wrote:
A popular Python library just became a backdoor to your entire machine
https://www.xda-developers.com/popular-python-library-backdoor-machine/
It's one of the most popular Python libraries for interacting with large language models [...] It has over 40,000 stars on GitHub, and it's an important dependency in a lot of AI tooling. It's also been compromised on PyPI, and the malicious versions are stealing everything they can find on your machine.
Sorry but... 🍿
![4-panel comic by @RoboTaterTotComics, an adventurer finding a treasure in a water-logged and crystal-studded cavern 1) "I've finally found it... After 15 years" 2) Adventurer holds up scroll, edited text reads: THE SCROLL OF [CHINESE CUISINE] 3) Close-up of the unfurled scroll, with edited text. [YOUR WOK ISN'T HOT ENOUGH] 4) Adventurer throws the scroll away in frustration, making a "NYEHHH" noise](https://files.mastodon.social/cache/media_attachments/files/116/287/747/510/849/209/original/74db6d9c4f0bbffe.png)







