logo

Grafana Labs Breach Exposes GitHub Repositories and Codebase

ID: 160161ce-5424-51e2-8ea8-556a81fd8e6a

STIX ID: report--160161ce-5424-51e2-8ea8-556a81fd8e6a

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-05-18

Date Updated: 2026-05-18

Author: Lucas Martin

...
...

A sophisticated attacker exploited a misconfigured GitHub Actions pull_request_target workflow at Grafana Labs by injecting a malicious curl in a forked repository, stealing a privileged token to download the company’s private codebase and demanding ransom; Grafana detected the breach via a triggered canary token, prevented further access, removed the vulnerable workflow, invalidated credentials, and reported no customer data was accessed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.