Grafana Confirms TanStack npm Supply Chain Attack Led to GitHub Repository Cloning
ID: 0d38d4cb-64fe-5546-ab5c-18427433d85b
STIX ID: report--0d38d4cb-64fe-5546-ab5c-18427433d85b
Feed Name: GBHackers
Grafana Labs confirmed that a May 11–16 supply-chain attack tied to the “Mini Shai-Hulud” campaign exploited leaked credentials on self‑hosted GitHub runners to clone and exfiltrate private internal repositories, prompting an extortion demand; Grafana rotated credentials, froze code, engaged Mandiant for independent forensics (which found no code tampering), contained the incident with no customer or production impact, and implemented long‑term mitigations such as short‑lived tokens and stricter access controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
