Cyber Incident Victim: Grafana Labs
Timeline
Summary
Grafana Labs disclosed that its GitHub repositories were compromised through a TanStack supply chain attack involving Mini Shai‑Hulud malware, which stole workflow tokens and allowed threat actors to download the company’s codebase, internal operational data and business contact names and email addresses. The attackers issued a ransom demand that was refused, and while no customer production systems or Grafana Cloud services were affected and no data was altered, the incident was limited to the source code and related internal information stored in GitHub.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 2 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 2 actors | Available to members | Available to members |
Description
On May 11, 2026, Grafana Labs detected malicious activity linked to a Mini Shai‑Hulud supply chain attack that had compromised TanStack npm packages. The attack involved threat actors from TeamPCP injecting credential‑stealing malware into dozens of TanStack packages, which were then automatically consumed by Grafana’s CI/CD pipelines. The malware exfiltrated GitHub workflow tokens, and although Grafana rotated many tokens immediately, one token remained active, allowing the attackers to access the company’s GitHub repositories. A later review revealed that a specific GitHub workflow initially thought to be unaffected had actually been compromised.

The attackers used the stolen tokens to download Grafana’s codebase and internal operational information stored in both public and private GitHub repositories. Among the data taken were business contact names and email addresses that would be exchanged in a professional relationship context, but no customer production data, personal information, or Grafana Cloud platform data was accessed. Grafana confirmed that the source code was not modified and that its production systems and the Grafana Cloud platform remained unaffected. The breach did not result in any leakage of customer data or disruption of Grafana’s services.
On May 15, 2026, the cybercrime group Coinbase Cartel listed Grafana Labs on its leak website, and two days later, on May 17, Grafana publicly confirmed the breach after the attackers claimed they had stolen data. The attackers demanded a ransom to prevent the source code from being leaked, but Grafana refused to pay. In response, Grafana rotated the remaining compromised credentials, hardened its GitHub security posture, launched additional mitigation efforts, and notified law enforcement. Grafana stated that a forensic analysis is underway and that it will share further details once the investigation concludes.
