market · May 20, 2026
Grafana Labs Breach Traced to TanStack npm Supply Chain Attack by TeamPCP on May 19, 2026
Share the canonical public link.
Grafana Labs investigation on May 19, 2026 linked its GitHub breach to the TanStack npm supply chain attack carried out by TeamPCP. Grafana Labs reported an extortion demand after detecting unauthorized access to internal repositories but refused to pay. The company rotated tokens and strengthened GitHub security controls following the incident. No evidence emerged of compromise to customer production systems or Grafana Cloud operations. The breach remained confined to Grafana Labs’ public and private GitHub repositories.