Back to Feed
Supply ChainMay 22, 2026

Grafana Says Codebase and Other Data Stolen via TanStack Supply Chain Attack

Grafana source code and data stolen after TanStack supply chain attack compromised a GitHub token.

Summary

Grafana disclosed that a compromised GitHub token, stemming from the TanStack supply chain attack, led to unauthorized access to its GitHub repositories. The attackers stole Grafana's codebase and internal operational information after Grafana detected the malicious activity and rotated most tokens, but missed one. Grafana refused to pay the ransom demand and has notified law enforcement.

Full text

Grafana this week revealed that the unauthorized access to the Grafana Labs GitHub repositories disclosed earlier this month was the result of the TanStack supply chain attack. On May 11, TanStack and other high-profile NPM and PyPI projects were hit by a Mini Shai-Hulud supply chain attack that resulted in self-propagating information-stealing malware being deployed on victims’ computers. Grafana says it detected malicious activity associated with the attack on May 11 and immediately rotated GitHub workflow tokens. Because one token was not revoked, however, the threat actor behind the TanStack attack accessed Grafana’s GitHub repositories. “A subsequent review confirmed that a specific GitHub workflow we originally deemed not impacted had, in fact, been compromised,” Grafana says. On May 16, Grafana received a ransom demand from the attackers, but refused to pay. Simultaneously, it launched additional mitigation efforts, hardened its GitHub posture, and notified law enforcement.Advertisement. Scroll to continue reading. “Current findings indicate the scope of this incident is limited to the Grafana Labs GitHub repositories, which include public and private source code along with internal GitHub repos,” Grafana says. While no customer production systems or operations were affected, the hackers did steal Grafana’s codebase, as well as repositories storing internal operational information and other business details. “This includes business contact names and email addresses that would be exchanged in a professional relationship context, not information pulled from or processed through the use of production systems or the Grafana Cloud platform,” Grafana says. The incident, it explains, did not affect its production systems, nor the Grafana Cloud platform. Furthermore, Grafana says, while its codebase was downloaded, it was not modified, and no action is needed from customers or open source users. Related: Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility Related: AI-Powered App Attacks Are Faster, More Frequent and Harder to Stop Related: Over 320 NPM Packages Hit by Fresh Mini Shai-Hulud Supply Chain Attack Related: OpenAI Hit by TanStack Supply Chain Attack Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Geordie Raises $30 Million for AI Security and Governance PlatformCarnival Data Breach Exposed 6 Million PeopleNew BTMOB Android Malware Enables Full Device TakeoverCritical FortiClient EMS Vulnerability Exploited in Fresh AttacksGitea Vulnerability Exposed 30,000 Deployments to AttacksGoogle Unveils AI Threat Defense Platform to Fight AI-Powered CyberattacksRevEng.AI Raises $15 Million to Hunt for Flaws and Backdoors in Software BinariesGlassWorm Botnet Disrupted Latest News Russian Spies Are Aggressively Seeking Western Technology as Sanctions Bite, Officials SayExploit Code Published for Critical Flowise RCE VulnerabilityIn Other News: Trump Mobile Data Breach, FIFA World Cup Phishing, CISA Responds to Supply Chain AttacksCharter Communications Data Breach Could Impact Nearly 5 MillionMokN Raises $15 Million for Phish-Back PlatformGogs Zero-Day Exposes Servers to Remote Code ExecutionCalifornia Sues 23andMe, Alleging It Failed to Protect User Data in 2023 BreachChrome 148 Update Patches 151 Vulnerabilities Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Threat Detection and Incident Response Summit On-Demand Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization. Register Webinar: Third-Party Risk in Practice June 4, 2026 Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice. Register People on the MoveAnurag Jain has been appointed Senior Vice President of Engineering at CodeHunterCTERA has appointed Tal Sarfaty as Senior Vice President of Cybersecurity.Quantum Secure Encryption has named Michael Massing as Chief Technology Officer.More People On The MoveExpert Insights Raising the Cybersecurity Stakes: Ante up for the Agentic Era CISOs are now facing machine-speed attacks and asking, “How do I agent?” The industry must provide remediation at scale. (Nadir Izrael) Caught Off Guard: Securing AI After It Hits Production As enterprises rush AI projects into production, security teams are increasingly being forced into reactive mode. (Joshua Goldfarb) Cyber Resilience is the New Business Continuity Plan The organizations best prepared to face disruption are those that align security, continuity and risk management around what the business cannot afford to lose. (Steve Durbin) Enhancing Data Center Security Without Sacrificing Performance For AI data centers, where the stakes are the highest and performance constraints are the tightest, security and performance are no longer a zero-sum game. (Nadir Izrael) Is the SOC Obsolete, and We Just Haven’t Admitted It Yet? Many AI-first enterprises have already embraced sovereign architectures for general AI initiatives; cybersecurity—and the SOC—should be next. (Danelle Au) Flipboard Reddit Whatsapp Whatsapp Email

Entities

Grafana (vendor)GitHub (technology)TanStack (campaign)