logo

Grafana breach caused by missed token rotation after TanStack attack

ID: 68c27345-28a8-5f3e-9cd5-f0f2aa5bdf45

STIX ID: report--68c27345-28a8-5f3e-9cd5-f0f2aa5bdf45

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Bill Toulas

...
...

Grafana disclosed a breach caused by a malicious TanStack npm package that executed an info-stealer in its CI/CD, exfiltrating GitHub workflow tokens; despite rotating many tokens, one missed token allowed attackers (attributed to TeamPCP / the Shai-Hulud campaign) to access private repositories and download source code and business contact information. Grafana reports no customer production systems were compromised and the codebase was not modified; the investigation is ongoing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.