Grafana Labs codebase stolen via missed GitHub token after TanStack supply-chain attack; ransom refused
Observability vendor Grafana Labs disclosed that an attacker used a GitHub workflow token it had failed to rotate after the TanStack npm supply-chain attack to download its public and private source code, then refused the resulting ransom demand.
- Victim
- Grafana Labs
On 17 May 2026, Grafana Labs, the company behind the open-source Grafana observability platform, disclosed that an unauthorized party had obtained a token granting access to its GitHub environment and used it to download the company's codebase, including proprietary code. The attacker then demanded a ransom to keep the code private; Grafana refused, citing FBI guidance that paying "doesn't guarantee" the return of data and encourages further attacks.
How it happened
Grafana was one of the organizations caught up in the TanStack npm supply-chain attack, part of the "Mini Shai-Hulud" campaign in which malicious versions of @tanstack/* packages harvested secrets from developer and CI environments. Grafana detected the malicious activity on 11 May and rotated a large number of GitHub workflow tokens, but one token was missed. The attacker used that token to reach the company's repositories.
The extortion group Coinbase Cartel claimed responsibility for the theft.
Impact
Grafana said the codebase was not altered and the incident was limited to its GitHub environment. Public and private source code was downloaded, along with internal repositories containing business contact names and email addresses exchanged in professional relationships. The company found no evidence that customer production systems, Grafana Cloud or customer personal data were affected.
Why it matters
The incident shows how a single supply-chain compromise keeps paying out for attackers: OpenAI, Mistral AI and Grafana were all hit through the same poisoned packages. Incomplete secret rotation turned a contained developer-machine infection into a full source-code theft, and Grafana's public refusal to pay made it one of the more transparent extortion cases of 2026.
Timeline
Grafana Labs detects malicious activity linked to the TanStack npm supply-chain attack and starts incident response.
The company receives a ransom demand threatening to leak its downloaded codebase and decides not to pay.
Grafana Labs publicly discloses that an attacker accessed its GitHub environment and downloaded its codebase.
Grafana confirms the compromise originated from the TanStack npm supply-chain attack.
Grafana publishes its post-incident review after completing the investigation with Mandiant's assistance.
Sources
- grafana.comhttps://grafana.com/blog/grafana-labs-security-update-latest-on-tanstack-npm-supply-chain-ransomware-incident/
- techcrunch.comhttps://techcrunch.com/2026/05/18/open-source-tool-maker-grafana-labs-says-hackers-stole-its-code-refuses-to-pay-ransom/
- helpnetsecurity.comhttps://www.helpnetsecurity.com/2026/05/18/attackers-accessed-downloaded-code-from-grafana-labs-github/
- thehackernews.comhttps://thehackernews.com/2026/05/grafana-github-breach-exposes-source.html