Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

The Hartley Center’s role in high-performance computing

Grafana GitHub breach exposes source code via TanStack npm attack

TeamPCP claims nearly 4,000 internal repositories have been compromised, GitHub is investigating

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Grafana GitHub breach exposes source code via TanStack npm attack
Identity

Grafana GitHub breach exposes source code via TanStack npm attack

By May 20, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Rabi LakshmananMay 20, 2026Supply chain attack/cloud security

Grafana Labs announced on May 19, 2026 that an investigation into a recent breach found no evidence that any of its customers’ production systems or operations were compromised.

The scope of the incident is limited to Grafana Labs’ GitHub environment, which includes public and private source code and internal GitHub repositories.

“After an initial assessment, we determined that the downloaded content, in addition to source code, included GitHub repositories used by some Grafana Labs teams to collaborate and store internal operational information and other details about our business,” the company said.

“This includes business contact names and email addresses exchanged in the course of business relationships, but does not include information obtained or processed through production systems or use of the Grafana Cloud platform.”

The open source visualization software maker also noted that this breach stemmed from a TanStack npm supply chain attack orchestrated by TeamPCP, which also attacked OpenAI and Mistral AI, and that it detected this activity on May 11, 2026.

“We performed analysis and quickly rotated a large number of GitHub workflow tokens, but the tokens were missing, allowing the attacker to access our GitHub repositories.” “Subsequent investigation confirmed that certain GitHub workflows that were initially thought to be unaffected were in fact compromised.”

The company later said it received an extortion request from an anonymous attacker on May 16, but did not agree to pay the ransom because there was no guarantee that the stolen data would actually be deleted and could serve as a springboard for future attacks.

Since then, Grafana has taken steps to strengthen the overall GitHub security posture, including automated token rotation, implementing enhanced monitoring, and auditing all commits for signs of malicious activity.

It is worth mentioning here that a data extortion team named CoinbaseCartel listed Grafana Labs on their dark website on May 15, 2026. Hacker News has contacted Grafana for comment and will update the article if we hear back.

The development comes after GitHub announced it was investigating unauthorized access to its internal repositories after a notorious threat actor known as TeamPCP listed the platform’s source code and internal organization for sale on a cybercrime forum.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleTeamPCP claims nearly 4,000 internal repositories have been compromised, GitHub is investigating
Next Article The Hartley Center’s role in high-performance computing

Related Posts

TeamPCP claims nearly 4,000 internal repositories have been compromised, GitHub is investigating

May 20, 2026

Trapdoor Android ad fraud scheme reaches 659 million bid requests per day using 455 apps

May 19, 2026

DirtyDecrypt PoC released for Linux kernel CVE-2026-31635 LPE vulnerability

May 19, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

The Hartley Center’s role in high-performance computing

Grafana GitHub breach exposes source code via TanStack npm attack

TeamPCP claims nearly 4,000 internal repositories have been compromised, GitHub is investigating

Elon Musk says Sam Altman ‘stole’ nonprofit organization – but trial reveals he had similar intentions

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.