Grafana Labs Says Code Breach Stemmed from TanStack Attack
ID: 13eee749-3c7f-50e1-a825-ceaa28327a39
STIX ID: report--13eee749-3c7f-50e1-a825-ceaa28327a39
Feed Name: Infosecurity Magazine (News)
Threat Score
A supply‑chain campaign dubbed Mini Shai‑Hulud (attributed to TeamPCP) compromised dozens of TanStack npm packages by inserting credential‑stealing malware into signed releases, which enabled exfiltration of CI/CD and cloud tokens and led to downstream compromises including Grafana Labs’ GitHub repositories and theft of internal operational contact data; the attackers have also attempted extortion.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
