logo

Grafana GitHub Action attempted supply chain attack (Incident)

ID: 8c93b7c7-be54-5b42-b318-f1f65445bb03

STIX ID: report--8c93b7c7-be54-5b42-b318-f1f65445bb03

Feed Name: Wiz Cloud Threat Landscape

Threat Score
65/100

Date Published: 2025-04-27

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Grafana Labs detected a supply-chain abuse involving a misconfigured GitHub Action that an attacker exploited by forking a repository, adding a malicious command to exfiltrate environment variables (including credentials), encrypting the data, and deleting the fork; the stolen credentials were then used to access four private repositories. Grafana reported no impact to production systems or customer data, revoked exposed tokens, disabled vulnerable workflows, and performed a full audit.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.