logo

Grafana GitHub Breach Linked to TanStack npm Supply Chain Ransomware

ID: 288353b7-4d9f-5dbe-8190-4aa20f95a8ec

STIX ID: report--288353b7-4d9f-5dbe-8190-4aa20f95a8ec

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Abinaya

...
...

**Grafana Labs disclosed a targeted supply-chain breach detected on May 11, 2026**, stemming from malicious TanStack npm packages that enabled attackers to compromise a CI/CD workflow token and access internal and private GitHub repositories; portions of source code, internal documentation, and business contact data were downloaded and a ransom demand was received on May 16. Grafana rotated automation tokens, audited repository activity, hardened CI/CD pipelines, and is cooperating with law enforcement, noting no impact to production systems or Grafana Cloud and no evidence of code modification.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.