Pythagora gpt-pilot GitHub Compromise

Confirmed
Discovered Jun 17, 2026

An attacker hijacked a Pythagora co-founder's GitHub account, force-pushed a Shai-Hulud credential-stealer to gpt-pilot's main branch, and lost the payload twice to ruff lint failures before any public downstream execution was shown.

1
Affected Packages
2
Observables
2
Sources

Timeline

1 of 1 rows

Timeline
DateEventDescriptionSource
Jun 17, 2026Fresh source reviewReviewed direct and primary sources for the last-two-weeks supply-chain refresh; this preview intentionally excludes older Halting Problems article data.Primary research

Affected Software

0 of 0 rows

Affected Software
PackageEcosystemVersion RangeStatusConfidenceSource
No rows match the active filters.

IOC Clipboard

2 IOCs
hash53154df1c66b42021f230c3fb6ef797c4b7c3e83
hash90f59f5de6819a43ffe9b6272e3ed65aaadca804

Provenance & Sources

2 of 2 rows

Provenance & Sources
SourceTypeReliabilityClaimsEvidence
Primary researchprimary research95%1https://www.stepsecurity.io/blog/pythagora-io-gpt-pilot-compromised-on-github-shai-hulud-credential-stealer-blocked-by-python-linter
Primary researchprimary research95%1https://github.com/Pythagora-io/gpt-pilot/issues/1182