Your AI Stack Was Backdoored for 3 Hours Yesterday. Were You Watching?
On March 24, attackers published poisoned versions of litellm to PyPI, compromising the transitive dependency tree of CrewAI, DSPy, Browser-Use, and a dozen other AI frameworks. The payload harvested credentials, deployed Kubernetes worms, and installed persistent backdoors.