Preview image for a blog post

Deep Dive: The `litellm` Python Supply-Chain Compromise and Runtime Hijacking via `.pth`

Analyzing the `litellm` Python supply-chain attack, its `.pth` vector, and crucial defenses: SBOMs, SLSA, SigStore.