LiteLLM Attack Transcript

Generative AI has enabled non security researchers to participate in security research. Watch what happens when an ML engineer uses Claude Code to help find and report an issue.

One of my favourite things is finding an article that contradicts the common thinking about an issue. In this case, I found a very interesting article, a minute by minute response to the LiteLLM malware attack.

The article is interesting, not only because of its detail but because of how important Claude Code was to the entire process. It not only helped uncover and prove the vulnerability, but helped the engineer who discovered it contact the right people and get it resolved properly.