Briefing

Grafana source‑code theft after stolen GitHub token and supply‑chain breach

security
by [email protected] (The Hacker News) ·

Verify Grafana GitHub tokens and rotate them immediately.

What to do now

Rotate all Grafana GitHub tokens and audit repository access logs.

Summary

Grafana Labs, the maker of the popular open‑source monitoring platform used by more than 7,000 organisations—including 70 % of the Fortune 50—has confirmed that hackers stole a GitHub workflow token and used it to download the company’s private source code. The breach was claimed by the extortion gang CoinbaseCartel, which added Grafana to its data‑leak site (DLS) but has not yet released any of the exfiltrated files. The attackers gained the token through a supply‑chain compromise involving the TanStack npm package, which contained an info‑stealer module that siphoned GitHub workflow tokens to the gang’s infrastructure. Although Grafana’s security team immediately rotated many tokens, one slipped through the rotation process, allowing the attackers to access private repositories.

The incident also involved the exfiltration of more than 3,800 internal repositories, though no customer data or personal information was compromised. No code modifications were made to Grafana’s production code, and the company confirmed that its customer systems remained unaffected. In response, Grafana invalidated the compromised credentials, added multi‑factor authentication, and tightened its token‑rotation procedures. The company chose not to pay the ransom, following FBI guidance, and pledged to release further details once its post‑incident investigation is complete.

CoinbaseCartel, active since last September, is known for using phishing, social engineering, and in‑memory tools such as “shinysp1d3r” to encrypt VMware ESXi targets. The gang has listed over 100 victims on its DLS and is notorious for targeting open‑source projects. The Grafana breach underscores the importance of securing repository access, monitoring for credential misuse, and enforcing rigorous token‑rotation policies after supply‑chain incidents. It also highlights the growing threat that open‑source ecosystems face from sophisticated extortion groups that combine credential theft with ransomware tactics.

Key changes

  • Grafana token theft exposed GitHub environment
  • Unauthorized party downloaded codebase
  • No customer data or personal information accessed
  • No evidence of impact to customer systems
  • Incident investigated by Grafana
  • Token used for GitHub access
  • Requires token rotation and audit

Affects

internal

Source angles · 8 perspectives

The Hacker News
Independent angle

Grafana GitHub Token Breach Led to Codebase Download and Extortion Attempt

Open
The Hacker News
Independent angle

GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension

Open
The Hacker News
Independent angle

Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer

Open
The Hacker News
Independent angle

Grafana GitHub Breach Exposes Source Code via TanStack npm Attack

Open
The Hacker News
Independent angle

GitHub Breached — Employee Device Hack Led to Exfiltration of 3,800+ Internal Repos

Open
Bleeping Computer
Independent angle

Grafana Says Stolen GitHub Token Let Hackers Steal Codebase

Open

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting