Grafana Confirms TanStack npm Supply Chain Ransom Incident Hit GitHub Environment

Grafana Labs has published a comprehensive post-incident review confirming that the TanStack npm supply chain ransom attack, which struck the company in May 2026, was strictly contained to its GitHub environment.

An independent investigation by Mandiant, the firm, has formally closed the incident with no evidence of customer data compromise or code tampering.

The attack chain began on May 11 when threat actors from the “Mini Shai-Hulud” campaign executed malicious code on Grafana’s self-hosted GitHub Actions runners, exfiltrating credentials.

Grafana Confirms TanStack npm Supply Chain

Although Grafana’s security team rotated the affected credentials at the time, one credential was inadvertently missed during the rotation sweep.

Exploiting that overlooked credential, the threat actor used the compromised grafana-delivery-bot account to initiate data exfiltration of Grafana’s entire repository collection starting May 14.

By May 15, the extortion demand had been published, and Grafana’s security team became aware of the ransom claim. The compromise was formally declared on May 16 at 17:39 UTC.

The threat actor demanded payment to prevent a public code leak. Despite maintaining private repositories for internal tools and proprietary Grafana Cloud features, the company declined to pay consistent with FBI guidance on ransomware response.

Grafana immediately suspended all GitHub applications on May 17, initiated a global code freeze on May 18, and launched a cross-platform audit spanning Vault, GitHub, Okta, Kubernetes, AWS, GCP, and host logs.

The remediation effort was substantial, encompassing 1,500 security-focused pull request reviews, audits of 280 GitHub applications with permissions stripped, scans across 1,200 repositories for signs of tampering, and 2,300 PR reviews conducted within a single critical repository.

Grafana stated that infrastructure audits were also completed with legacy systems retired throughout the process.

To ensure independent validation, Grafana engaged Mandiant beginning June 1, providing API access to its log environment for a full forensic review.

Mandiant concluded its investigation on June 18, confirming “no evidence of code tampering or repository poisoning within public organizations or production repositories delivered to end users.”

While the downloaded content included source code and internal operational data, such as business contact names and email addresses from past marketing campaigns, Grafana confirmed that this information was not sourced from production systems.

With the investigation now closed, Grafana outlined a series of structural security improvements it has already begun implementing.

These include deploying a token broker for short-lived, fine-grained GitHub credentials, migrating away from certain GitHub Actions to more tightly scoped alternatives that use short-lived tokens, compartmentalizing GitHub organizations, and isolating all archived repositories into a dedicated organization with Actions disabled.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories