Grafana Labs has disclosed a targeted ransomware-linked breach of its GitHub environment, traced to a broader TanStack npm supply chain compromise associated with the “Mini Shai-Hulud” campaign.
The incident, detected on May 11, 2026, involved unauthorized access to internal repositories and culminated in a ransom demand issued on May 16 under threat of data disclosure.
According to Grafana Labs, the intrusion originated from malicious packages distributed through the TanStack npm ecosystem.
These packages were part of an ongoing supply-chain attack that enabled threat actors to inject malicious code into development workflows.
Despite rapid token rotation efforts, a previously overlooked CI/CD workflow was later confirmed to have been compromised, enabling the attackers to exfiltrate repository data.
Grafana confirmed that attackers downloaded portions of its codebase along with internal operational repositories.
The exposed data includes:
The company emphasized that no production systems, customer environments, or Grafana Cloud infrastructure were impacted.
Additionally, there is no evidence that the attackers modified any source code.
On May 16, Grafana Labs received a ransom demand from the threat actors, who threatened to publicly release the stolen data.
The company has refused to comply with the demand, aligning with FBI guidance that discourages ransom payments due to the lack of guarantees and the potential to encourage further criminal activity.
Grafana immediately escalated its incident response :
Federal law enforcement agencies have been notified, and Grafana is cooperating with ongoing investigations.
This incident highlights the growing risk of software supply chain attacks targeting developer ecosystems.
Compromised npm packages remain a critical attack vector, particularly when integrated into automated CI/CD workflows.
For example, a single malicious dependency in a build pipeline can expose authentication tokens or secrets, allowing attackers to pivot into source code repositories without directly breaching infrastructure.
Grafana Labs stated that its investigation is ongoing, with continued analysis of logs, telemetry, and repository activity. A detailed post-incident report will be released upon completion.
The company reiterated that no action is currently required from customers or open-source users, as there is no indication of downstream compromise.
As supply chain attacks continue to evolve, the Grafana breach underscores the importance of strict dependency validation, token management, and CI/CD security hardening across modern development environments.
Follow us on Google News, LinkedIn, and X to Get More Instant Updates.
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…
CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…
Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…
You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…
Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…