market · May 21, 2026
Grafana Labs confirms security breach linked to TanStack npm attack
Share the canonical public link.
Grafana Labs stated on May 19, 2026 that an investigation into its recent breach found no evidence of customer production systems or operations being compromised. The company said attackers accessed parts of its GitHub environment including public and private source code repositories. Grafana Labs said security teams quickly rotated several GitHub workflow tokens to stop the intrusion after detecting suspicious activity on May 11, 2026. Grafana Labs said investigators found no signs of compromise inside customer production systems or the Grafana Cloud platform.