market · May 21, 2026
Grafana Labs confirms GitHub breach from TanStack npm supply chain attack
Share the canonical public link.
Grafana Labs confirmed on May 16, 2026, that a cybercrime group gained unauthorized access to its GitHub repositories via a missed GitHub workflow token and downloaded portions of its codebase. The breach originated from the TanStack npm supply chain attack in the Mini Shai-Hulud campaign detected on May 11, 2026, with attackers from TeamPCP exploiting the unrotated token after initial rotations. Grafana Labs received a ransom demand on May 16 from the CoinbaseCartel group but refused payment following FBI guidance, rotated remaining tokens, audited all commits since May 11, and hardened its GitHub security posture including CI/CD pipelines. No customer production systems, operations, or Grafana Cloud platform data were compromised, though internal operational information such as business contact names and emails was accessed. Grafana Labs CISO Joe McManus detailed the response in the May 19, 2026 update, and the company notified federal law enforcement.