logo

The Missed Token: Grafana Labs Suffers Source Code Theft via Shai-Hulud npm Worm Campaign

ID: df21805a-db62-5ae1-96d0-ae7424c7e26d

STIX ID: report--df21805a-db62-5ae1-96d0-ae7424c7e26d

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Ddos

...
...

Grafana Labs suffered a supply-chain breach beginning May 11, 2026 when a poisoned npm package from the Mini Shai-Hulud campaign allowed attackers—via a missed GitHub workflow token—to clone and exfiltrate proprietary source code and internal business repositories; attackers issued a ransom demand on May 16, Grafana refused to pay, rotated tokens, and reports no production/cloud customer systems or code integrity were compromised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.