market · May 22, 2026
Grafana Labs links GitHub environment breach to TanStack npm supply chain attack
Share the canonical public link.
Grafana Labs stated on May 21, 2026, that its earlier GitHub environment breach originated from the TanStack npm supply chain attack linked to the Mini Shai-Hulud compromise by threat group TeamPCP. The company detected malicious activity on May 11, 2026, rotated a significant number of GitHub workflow tokens but missed one, allowing attackers to access repositories and download source code plus internal operational data. Hackers contacted Grafana on May 16 with an extortion demand, which the company refused per FBI guidance that payment would only incentivize further attacks. The incident was limited to GitHub repositories with no impact on more than 7,000 customers including Nvidia, Microsoft, and Anthropic or on production systems. Grafana implemented enhanced monitoring, committed audits, and CI/CD pipeline security improvements as part of its response.