THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-93qj-5q5v-3c2h (critical) — Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise)

[GHSA] GHSA-93qj-5q5v-3c2h (critical) — Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise)

medgithub_advisoriesPublished 2026-08-26

GHSA-93qj-5q5v-3c2h Severity: critical CVE: None

Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise)

## Summary The PyPI account that publishes `pantheon-agents` was compromised in the June 2026 "Hades" PyPI supply-chain attack (Mini Shai-Hulud / Miasma lineage). The attacker used a stolen, long-lived PyPI API token to upload **trojanize

MITRE ATT&CK techniques

Original source: https://github.com/advisories/GHSA-93qj-5q5v-3c2h