Grafana Labs disclosed a security incident originating from the TanStack npm supply chain attack (Mini Shai-Hulud campaign). Attackers gained unauthorized access to Grafana Labs' GitHub repositories and downloaded source code and internal operational data, then issued a ransom demand. Grafana Labs refused to pay, notified federal law enforcement, and confirmed no customer production systems or Grafana Cloud platform were compromised. Mitigation steps included rotating GitHub workflow tokens, auditing all commits since May 11, enhancing monitoring, and hardening CI/CD pipelines. An external audit by Mandiant is underway, with a post-incident report expected in June 2026.

4m read timeFrom grafana.com
Post cover image
Table of contents
Summary and backgroundImpact and response
7.7K Impressions