frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

One-liners to check for bad litellm and axios on your computer

1•jbdamask•1h ago
Search your drive (not mounts) for compromised versions of litellm and axios.

Please comment if you see anything wrong or ways these can be improved!

LiteLLM: find / \( -type d -name "litellm-.dist-info" -o -name "litellm_init.pth" \) 2>/dev/null \ | while read d; do case "$d" in dist-info) v=$(echo "$d" | sed 's/.litellm-\(.\)\.dist-info/\1/') if echo "$v" | grep -qE '^1\.82\.(7|8)$'; then echo "COMPROMISED: $d -> litellm $v" else echo "CLEAN: $d -> litellm $v" fi ;; pth) echo "COMPROMISED: malicious .pth file found at $d" ;; esac done

Example output: CLEAN: /System/Volumes/Data/Users/johndamask/code/my-own-agents-shove-it/openai-agents-sdk/thebostonwrongs/.venv/lib/python3.12/site-packages/litellm-1.67.5.dist-info -> litellm 1.67.5 CLEAN: /System/Volumes/Data/Users/johndamask/code/ai-evals-course/recipe-chatbot-langchain/.venv/lib/python3.12/site-packages/litellm-1.78.5.dist-info -> litellm 1.78.5 CLEAN: /System/Volumes/Data/Users/johndamask/code/ai-evals-course/recipe-chatbot/.venv/lib/python3.12/site-packages/litellm-1.73.6.dist-info -> litellm 1.73.6

Axios: find . -path "

/node_modules/axios/package.json" 2>/dev/null \ | while read f; do v=$(grep '"version"' "$f" | head -1 | sed 's/.: "\(.\)"./\1/') dir=$(dirname "$f") if echo "$v" | grep -qE '^(1\.14\.1|0\.30\.4)$'; then echo "COMPROMISED: $dir -> axios $v" else echo "CLEAN: $dir -> axios $v" fi done

The Upside to San Francisco's Unwelcome Airport Capacity Cut

https://crankyflier.com/2026/04/02/the-upside-to-san-franciscos-unwelcome-airport-capacity-cut/
1•walterbell•31s ago•0 comments

Show HN: I built a Cargo supply chain auditor using Claude and GitHub Actions

https://github.com/originsec/cargo-lock-supply-chain-claude
1•T-RN-R•1m ago•0 comments

Do I Need a Contract?

https://b2bs.substack.com/p/operator-note-do-i-really-need-a
1•oopsiremembered•2m ago•0 comments

Exposing the FBI's Human Experimentation Studies

https://www.racket.news/p/exclusive-exposing-the-fbis-human
1•t-3•3m ago•0 comments

The Internet Bug Bounty paused indefinitely

https://hackerone.com/ibb
1•pimterry•3m ago•0 comments

The OG Immersion Method

https://www.dreaming.com/blog-posts/the-og-immersion-method
1•Cider9986•3m ago•0 comments

Libinput Hit by Worrying Security Issues with Its Lua Plug-In System

https://www.phoronix.com/news/Libinput-Lua-Security-Issues
1•t-3•4m ago•0 comments

CSS subgrid is super good

https://dbushell.com/2026/04/02/css-subgrid-is-super-good/
1•speckx•4m ago•0 comments

Vtables Aren't Slow (Usually)

https://louis.co.nz/2026/01/24/vtable-overhead.html
1•hmpc•5m ago•0 comments

Gloamy: An open source Claude Cowork alternative

https://github.com/iBz-04/gloamy
1•Ibz04•7m ago•1 comments

Aragorn's Tax Policy and Other Weird Shibboleths

https://reactormag.com/aragorns-tax-policy-and-other-weird-shibboleths/
1•baud147258•7m ago•0 comments

Apple at 50: My journey to the Mac

https://anderegg.ca/2026/04/01/apple-at-50-my-journey-to-the-mac
1•Brajeshwar•7m ago•0 comments

Oil prices soar and shares drop after Trump threatens more Iran strikes

https://www.bbc.com/news/articles/ce8lzd4v7zdo
1•tartoran•8m ago•0 comments

Show HN: Topical.so - structural SEO audits for AI-generated blogs

1•adriaanb•8m ago•0 comments

A life insurance fraud ring built on fake restaurants

https://connordempsey.substack.com/p/how-to-commit-insurance-fraud
1•cdempsey44•9m ago•0 comments

The Self-Cancelling Subscription

https://predr.ag/blog/the-self-cancelling-subscription/
1•birdculture•11m ago•0 comments

Peaky Peek – Local-first debugger for AI agents

https://github.com/acailic/agent_debugger
1•ilkehimself•13m ago•0 comments

Andon (Manufacturing)

https://en.wikipedia.org/wiki/Andon_(manufacturing)
1•debo_•14m ago•0 comments

You can use AI every day and still not get better

https://www.kevinlondon.com/2026/03/12/ai-every-day-and-not-get-better/
2•Kaedon•15m ago•0 comments

Congressional scrutiny of Kalshi, Polymarket explodes

https://www.politico.com/news/2026/04/01/congress-kalshi-polymarket-regulation-00852370
1•1vuio0pswjnm7•15m ago•0 comments

Artemis computer running two instances of MS outlook; they can't figure out why

https://bsky.app/profile/nikigrayson.com/post/3miik2wzosk25
9•mooreds•15m ago•4 comments

As arms agreements fray, China expands its nuclear weapons infra

https://www.cnn.com/2026/04/01/china/investigates-china-secretly-expanding-nuclear-weapons-infras...
1•cwwc•16m ago•0 comments

WebKit Features for Safari 26.4

https://webkit.org/blog/17862/webkit-features-for-safari-26-4/
2•ksec•17m ago•1 comments

Artemis II will use laser beams to live-stream 4K moon footage at 260 Mbps

https://www.tomshardware.com/networking/artemis-ii-will-use-laser-beams-to-live-stream-4k-moon-fo...
4•speckx•19m ago•0 comments

In a thunderous launch, Artemis II astronauts leave Earth. Here's what's next

https://text.npr.org/nx-s1-5770599
1•mooreds•20m ago•0 comments

Delve allegedly forked an open-source tool and sold it as its own

https://techcrunch.com/2026/04/01/the-reputation-of-troubled-yc-startup-delve-has-gotten-even-worse/
5•nickvec•21m ago•0 comments

There Is No Standard EM Role

https://leadership.garden/there-is-no-standard-em-role/
2•speckx•22m ago•0 comments

Best Enterprise Claude Code Gateway

https://www.npmjs.com/package/@maximhq/bifrost
1•aanthonymax•25m ago•0 comments

Node.js can host a new language. Interpreter is the easiest thing

https://github.com/dominexmacedon-dev/starlight-cli-script
1•dominexmacedon•25m ago•0 comments

Startup funding shatters all records in Q1

https://techcrunch.com/2026/04/01/startup-funding-shatters-all-records-in-q1/
1•Brajeshwar•26m ago•1 comments