logo

Grafana Confirms TanStack npm Supply Chain Attack Led to GitHub Repository Cloning

ID: 0d38d4cb-64fe-5546-ab5c-18427433d85b

STIX ID: report--0d38d4cb-64fe-5546-ab5c-18427433d85b

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-06-24

Date Updated: 2026-06-24

Author: Divya

...
...

Grafana Labs confirmed that a May 11–16 supply-chain attack tied to the “Mini Shai-Hulud” campaign exploited leaked credentials on self‑hosted GitHub runners to clone and exfiltrate private internal repositories, prompting an extortion demand; Grafana rotated credentials, froze code, engaged Mandiant for independent forensics (which found no code tampering), contained the incident with no customer or production impact, and implemented long‑term mitigations such as short‑lived tokens and stricter access controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.