logo

GitHub, Grafana Labs breaches traced back to TanStack supply chain compromise

ID: df206e6a-d9fe-5313-a820-802944baac7c

STIX ID: report--df206e6a-d9fe-5313-a820-802944baac7c

Feed Name: Help Net Security

Threat Score
90/100

Date Published: 2026-05-21

Date Updated: 2026-05-21

Author: Zeljka Zorz

...
...

A poisoned VS Code extension (Nx Console) and malicious TanStack npm package releases—attributed to TeamPCP and the Mini Shai-Hulud self-replicating worm—were used to harvest credentials (tokens, cloud and package credentials, secrets managers) and pivot through CI/CD pipelines, leading to the exfiltration of around 3,800 private GitHub repositories and impacting organizations including GitHub and Grafana Labs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.