Grafana says stolen GitHub token let hackers steal codebase
ID: e2175f35-8b18-5502-98ea-f142b5ccdd09
STIX ID: report--e2175f35-8b18-5502-98ea-f142b5ccdd09
Feed Name: Bleeping Computer
Grafana Labs disclosed that attackers used a stolen GitHub access token to exfiltrate its source code and that extortion group CoinbaseCartel claimed the theft; Grafana says no customer data or systems were affected, has invalidated credentials, and refused to pay the ransom while continuing its post-incident investigation. CoinbaseCartel — reportedly composed of ShinyHunters and Lapsus$ affiliates — is active and uses credential compromise, phishing, and in-memory tools like “shinysp1d3r” to attack targets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
