Menu
Browse

Cyber Incident Victim: Grafana Labs

Date

May 2026

Location

United States of America

Status

Unknown

Updated

2026-07-18 00:41

Timeline
Occurred
May 2026
Discovered
Pending
Disclosed
Pending
Resolved
Pending
Summary

Grafana Labs disclosed that its GitHub repositories were compromised through a TanStack supply chain attack involving Mini Shai‑Hulud malware, which stole workflow tokens and allowed threat actors to download the company’s codebase, internal operational data and business contact names and email addresses. The attackers issued a ransom demand that was refused, and while no customer production systems or Grafana Cloud services were affected and no data was altered, the incident was limited to the source code and related internal information stored in GitHub.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 2 techniques
Threat Actors Type Location
2 actors Available to members Available to members

Description

On May 11, 2026, Grafana Labs detected malicious activity linked to a Mini Shai‑Hulud supply chain attack that had compromised TanStack npm packages. The attack involved threat actors from TeamPCP injecting credential‑stealing malware into dozens of TanStack packages, which were then automatically consumed by Grafana’s CI/CD pipelines. The malware exfiltrated GitHub workflow tokens, and although Grafana rotated many tokens immediately, one token remained active, allowing the attackers to access the company’s GitHub repositories. A later review revealed that a specific GitHub workflow initially thought to be unaffected had actually been compromised.

Cyber Incident Image

The attackers used the stolen tokens to download Grafana’s codebase and internal operational information stored in both public and private GitHub repositories. Among the data taken were business contact names and email addresses that would be exchanged in a professional relationship context, but no customer production data, personal information, or Grafana Cloud platform data was accessed. Grafana confirmed that the source code was not modified and that its production systems and the Grafana Cloud platform remained unaffected. The breach did not result in any leakage of customer data or disruption of Grafana’s services.

On May 15, 2026, the cybercrime group Coinbase Cartel listed Grafana Labs on its leak website, and two days later, on May 17, Grafana publicly confirmed the breach after the attackers claimed they had stolen data. The attackers demanded a ransom to prevent the source code from being leaked, but Grafana refused to pay. In response, Grafana rotated the remaining compromised credentials, hardened its GitHub security posture, launched additional mitigation efforts, and notified law enforcement. Grafana stated that a forensic analysis is underway and that it will share further details once the investigation concludes.

Sources
Sources available to members
3 sources