The Missed Token: Grafana Labs Suffers Source Code Theft via Shai-Hulud npm Worm Campaign
ID: df21805a-db62-5ae1-96d0-ae7424c7e26d
STIX ID: report--df21805a-db62-5ae1-96d0-ae7424c7e26d
Feed Name: securityonline.info
Threat Score
Grafana Labs suffered a supply-chain breach beginning May 11, 2026 when a poisoned npm package from the Mini Shai-Hulud campaign allowed attackers—via a missed GitHub workflow token—to clone and exfiltrate proprietary source code and internal business repositories; attackers issued a ransom demand on May 16, Grafana refused to pay, rotated tokens, and reports no production/cloud customer systems or code integrity were compromised.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
