HomeSecurityGrafana: Code theft via TanStack supply chain attack

Grafana: Code theft via TanStack supply chain attack

Grafana revealed this week that unauthorized access to the company’s GitHub repositories was the result of the TanStack supply chain attack that hit several high-profile platforms. The attackers managed to steal Grafana ’s source code as well as internal data , but did not affect customers’ production systems. The incident highlights the growing threat of supply chain attacks targeting software development ecosystems and developer collaboration platforms.

Grafana TanStack

On May 11, TanStack and other high-profile NPM and PyPI projects were hit by the Mini Shai-Hulud. This attack resulted in the deployment of self-propagating information-stealing malware on victims' computers.

Grafana detected malicious activity on May 11 and immediately rotated GitHub workflow tokens . However, because one token was not revoked, the threat actor gained access to Grafana's GitHub repositories .

See also: OpenAI confirms breach via TanStack supply chain attack

The company's rapid response demonstrates the maturity of its security procedures, but at the same time highlights how easily a single overlooked token compromise the entire defense strategy.

As the company explains, “a subsequent review confirmed that a specific GitHub workflow that we initially believed to be unaffected had in fact been compromised.” This highlights the importance of thoroughly analyzing all systems following a security incident, as initial assessments may prove to be inadequate. The complexity of modern CI/CD systems makes it difficult to fully document all access points.

Grafana supply chain attack TanStack GitHub repositories

Ransom demand and Grafana's response

On May 16, the attackers approached Grafana and demanded a ransom, but the company refused to pay. At the same time, it initiated additional mitigation efforts, strengthened GitHub , and notified law enforcement. The decision not to pay the ransom was based on the principle that paying does not guarantee the deletion of stolen data and may fund further attacks. This stance is consistent with the recommendations of law enforcement and cybersecurity experts, who emphasize that paying ransoms encourages continued criminal activity.

See also: DAEMON Tools Supply Chain Attack: Government organizations targeted

According to current findings, the scope of the incident is limited to GitHub repositories , which include public and private source code along with internal GitHub repos. No production customer systems were affected, but the hackers were able to steal Grafana code, as well as repositories that store internal operational information and other business details. The stolen data includes business contact names and email that would be exchanged in a professional context, not information originating from production systems or the Grafana Cloud platform.

Grafana - SecNews.gr

TanStack in its analysis described the attack as a chain of three vulnerabilities/configuration issues, each of which was necessary for success: a vulnerable PR workflow pattern , cache poisoning at trust boundaries, and token extraction from runner memory . The attack also affected other high-profile companies, including OpenAI and Mistral AI .

See also: Google attributes Axios Supply Chain Attack to UNC1069

Advanced protection techniques for organizations

To effectively protect against such attacks, organizations should adopt a multi-layered security approach. First, implementing short-lived tokens with limited privileges can significantly reduce the attack surface. Second, using GitHub App installations instead of broad-scope Personal Access Tokens (PATs) provides better control and monitoring. Third, implementing network segmentation between development and production environments can limit the spread of a breach. Fourth, regularly conducting security audits of GitHub Actions workflows and using static analysis tools to identify vulnerable patterns are critical.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS