pantheon-agents PyPI Package Compromised: Early Warning
- Severity
- CRITICAL
- Affected component
- pantheon-agents (pypi)
- Affected versions
- >= 0.6.1, <= 0.6.1 or >= 0.6.2, <= 0.6.2 or >= 0.6.1, <= 0.6.1 or >= 0.6.2, <= 0.6.2
- Patched version
- Not yet available
The PyPI account that publishes pantheon-agents was reportedly compromised. Versions 0.6.1 and 0.6.2 contain a credential stealer.
What happened
The PyPI account responsible for publishing the pantheon-agents package appears to have been compromised in the June 2026 'Hades' PyPI supply-chain attack. The attacker uploaded trojanized releases 0.6.1 and 0.6.2 to PyPI, which contain a credential stealer. This incident is under investigation and has not yet been confirmed. Software engineers using pantheon-agents should assess their exposure to these specific versions.
The trojanized versions, 0.6.1 and 0.6.2, are the only ones known to be affected at this time. The attack vector was a supply-chain compromise, meaning the malicious code was introduced through the official distribution channel. There is no indication that these versions have been exploited in the wild, but the severity is classified as critical due to the nature of the payload.
What to do about it
- Do not install pantheon-agents from PyPI until distribution resumes.
- If you have installed versions 0.6.1 or 0.6.2, uninstall them immediately.
- Rotate all credentials on any machine that installed the affected versions.
- Monitor the primary sources for updates on the situation and any official fixes.
- Consider using alternative packages or sources for your dependency needs until the situation is resolved.
How 0Day would have caught this
pantheon-agents is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are affected if you have installed pantheon-agents versions 0.6.1 or 0.6.2 from PyPI.
What should I do right now?
Uninstall versions 0.6.1 or 0.6.2 of pantheon-agents and rotate all credentials on the affected machine. Do not install pantheon-agents from PyPI until further notice.
Is there an official fix available?
No official fix has been published yet. Monitor the primary sources for updates.
How was this attack carried out?
The attack was carried out through a supply-chain compromise, where malicious code was uploaded to the official PyPI distribution channel.