Skip to main content

System status

Coverage is stale.

Collection is paused. Latest public event: Aug 21, 2026 (10 days ago).

← Intel index

This coverage is stale.

Last updated May 21, 2026 (about 3 months ago).

market · May 21, 2026

Grafana Labs confirms GitHub breach from TanStack npm supply chain attack

Share the canonical public link.

Share as image

Grafana Labs confirmed on May 16, 2026, that a cybercrime group gained unauthorized access to its GitHub repositories via a missed GitHub workflow token and downloaded portions of its codebase. The breach originated from the TanStack npm supply chain attack in the Mini Shai-Hulud campaign detected on May 11, 2026, with attackers from TeamPCP exploiting the unrotated token after initial rotations. Grafana Labs received a ransom demand on May 16 from the CoinbaseCartel group but refused payment following FBI guidance, rotated remaining tokens, audited all commits since May 11, and hardened its GitHub security posture including CI/CD pipelines. No customer production systems, operations, or Grafana Cloud platform data were compromised, though internal operational information such as business contact names and emails was accessed. Grafana Labs CISO Joe McManus detailed the response in the May 19, 2026 update, and the company notified federal law enforcement.

Below validation threshold — auto-passed without scoring

Supporting evidence