logo

Grafana says stolen GitHub token let hackers steal codebase

ID: e2175f35-8b18-5502-98ea-f142b5ccdd09

STIX ID: report--e2175f35-8b18-5502-98ea-f142b5ccdd09

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-05-18

Date Updated: 2026-05-18

Author: Bill Toulas

...
...

Grafana Labs disclosed that attackers used a stolen GitHub access token to exfiltrate its source code and that extortion group CoinbaseCartel claimed the theft; Grafana says no customer data or systems were affected, has invalidated credentials, and refused to pay the ransom while continuing its post-incident investigation. CoinbaseCartel — reportedly composed of ShinyHunters and Lapsus$ affiliates — is active and uses credential compromise, phishing, and in-memory tools like “shinysp1d3r” to attack targets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.