Grafana GitHub Action attempted supply chain attack (Incident)
ID: 8c93b7c7-be54-5b42-b318-f1f65445bb03
STIX ID: report--8c93b7c7-be54-5b42-b318-f1f65445bb03
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-04-27
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Grafana Labs detected a supply-chain abuse involving a misconfigured GitHub Action that an attacker exploited by forking a repository, adding a malicious command to exfiltrate environment variables (including credentials), encrypting the data, and deleting the fork; the stolen credentials were then used to access four private repositories. Grafana reported no impact to production systems or customer data, revoked exposed tokens, disabled vulnerable workflows, and performed a full audit.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
