Skip to main content

System status

Coverage is stale.

Collection is paused. Latest public event: Aug 21, 2026 (10 days ago).

← Intel index

This coverage is stale.

Last updated May 22, 2026 (about 3 months ago).

market · May 22, 2026

Grafana Labs links GitHub environment breach to TanStack npm supply chain attack

Share the canonical public link.

Share as image

Grafana Labs stated on May 21, 2026, that its earlier GitHub environment breach originated from the TanStack npm supply chain attack linked to the Mini Shai-Hulud compromise by threat group TeamPCP. The company detected malicious activity on May 11, 2026, rotated a significant number of GitHub workflow tokens but missed one, allowing attackers to access repositories and download source code plus internal operational data. Hackers contacted Grafana on May 16 with an extortion demand, which the company refused per FBI guidance that payment would only incentivize further attacks. The incident was limited to GitHub repositories with no impact on more than 7,000 customers including Nvidia, Microsoft, and Anthropic or on production systems. Grafana implemented enhanced monitoring, committed audits, and CI/CD pipeline security improvements as part of its response.

Below validation threshold — auto-passed without scoring

Supporting evidence