Grafana GitHub Security Incident Reportedly Connected to TanStack npm Ransomware
ID: f26e3fb0-99c7-580d-853a-82f4a1a35652
STIX ID: report--f26e3fb0-99c7-580d-853a-82f4a1a35652
Feed Name: GBHackers
Grafana Labs disclosed a May 11, 2026 GitHub security incident tied to the TanStack "Mini Shai-Hulud" supply chain ransomware campaign in which attackers used a compromised GitHub Actions workflow token to access and download public and private source code, internal operational repositories, and business contact data; a ransom demand followed on May 16, Grafana refused to pay, and the company reports no evidence of code tampering or customer impact while pursuing token rotation, audits, enhanced monitoring, CI/CD hardening, and law enforcement notification.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
