pantheon-agents

PyPI Compromised

1

report

Attack type: Malicious version

Reports

Malicious version Versions: >= 0.6.1, <= 0.6.2 1d ago by isitcompromised.com

Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise) ## Summary The PyPI account that publishes `pantheon-agents` was compromised in the June 2026 "Hades" PyPI supply-chain attack (Mini Shai-Hulud / Miasma lineage). The attacker used a stolen, long-lived PyPI API token to upload **trojanized releases `pantheon-agents` 0.6.1 and 0.6.2 directly to PyPI**. **Only the PyPI artifacts are affected.** The GitHub source repository, its git tags, and all other distribution channels are clean — no malicious code was committed to the repository. ## Affecte

View evidence

Have more info?

Submit additional evidence or a new report for this package.

Submit a report