THREAT OPS › Threat News › [GHSA] GHSA-93qj-5q5v-3c2h (critical) — Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise)
[GHSA] GHSA-93qj-5q5v-3c2h (critical) — Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise)
GHSA-93qj-5q5v-3c2h Severity: critical CVE: None
Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise)
## Summary The PyPI account that publishes `pantheon-agents` was compromised in the June 2026 "Hades" PyPI supply-chain attack (Mini Shai-Hulud / Miasma lineage). The attacker used a stolen, long-lived PyPI API token to upload **trojanize
MITRE ATT&CK techniques
Original source: https://github.com/advisories/GHSA-93qj-5q5v-3c2h