Grafana GitHub Breach Exposes Source Code via TanStack npm Attack
Below validation threshold — auto-passed without scoring
Grafana Labs reported on May 19, 2026, that an investigation found no evidence of customer production systems or operations being compromised in its recent breach. The scope remained limited to the Grafana Labs GitHub environment including public and private source code plus internal repositories used for collaboration and operational information such as business contact names and email addresses. The breach traced back to the TanStack npm supply chain attack with malicious activity detected on May 11, 2026, after which a missed token rotation enabled access. CoinbaseCartel listed Grafana on its dark web extortion site on May 15, 2026, and issued a ransom demand on May 16 which Grafana refused. The company rotated tokens, audited commits, and hardened its GitHub posture while confirming the codebase was downloaded but not altered.