logo

Grafana GitHub Security Incident Reportedly Connected to TanStack npm Ransomware

ID: f26e3fb0-99c7-580d-853a-82f4a1a35652

STIX ID: report--f26e3fb0-99c7-580d-853a-82f4a1a35652

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Divya

...
...

Grafana Labs disclosed a May 11, 2026 GitHub security incident tied to the TanStack "Mini Shai-Hulud" supply chain ransomware campaign in which attackers used a compromised GitHub Actions workflow token to access and download public and private source code, internal operational repositories, and business contact data; a ransom demand followed on May 16, Grafana refused to pay, and the company reports no evidence of code tampering or customer impact while pursuing token rotation, audits, enhanced monitoring, CI/CD hardening, and law enforcement notification.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.