Svmuureports that Grafana Labs posted on X, stating that it confirmed a targeted hacker attack on May 16. The attacker gained unauthorized access to its GitHub repository and downloaded the codebase through a TanStack npm supply chain attack (Mini Shai-Hulud campaign), subsequently issuing a ransom threat.
Investigations indicate that this incident was strictly limited to Grafana Labs' GitHub environment, with no evidence suggesting it affected customer production systems, operations, or the Grafana Cloud platform. The downloaded content, in addition to source code, also included the names and email addresses of some internal business contacts. Although the attacker downloaded the codebase, it was not tampered with. Grafana Labs has decided not to pay the ransom and has notified federal law enforcement authorities. It is currently implementing defensive measures, including enhancing CI/CD pipeline security.
Disclaimer:All content on this platform is sourced from the internet and is provided for informational purposes only. None of the content represents the views of this site, nor does it constitute investment advice. Please exercise caution when investing.
Grafana: Suffered a supply chain attack, but the security incident did not affect customer production systems or operations
Disclaimer: This content reflects the author's personal views only and does not constitute investment advice. If you find any violations, please Click to Report
24H Trending
-
Binance Seven U-denominated perpetual contracts, including LRCX and KLAC, will be launched
-
Gate's Stock Contracts Section Launches Trading for 8 Perpetual Contracts, Including ADSK (Autodesk) and BKNG (Booking.com Holdings)
-
Learn More About the ALTHEA Token (ALTH) and Its Decentralized Network
-
The OKX DEX xStocks Trading Competition is currently underway, with a total prize pool of 300,000 USDC
-
Morgan Stanley Updates Ethereum and Solana ETF Filings, Proposing a 0.14% Fee
-
Record-High AI-Driven Leveraged Bets in Asia: SK Hynix’s 2x Long ETF in South Korea Reaches $13 Billion in Assets Under Management
-
A "smart money" investor bet $320,000 on Argentina to beat Austria in the World Cup group stage
-
Market News: U.S. Vice President Vance is set to deliver a speech in Switzerland following his first round of talks with Iran
-
Mainland China’s Dogecoin Trading Platform: Current Status—Regulatory Policies and Global Mainstream Options
-
Iranian media report that Iran-U.S. negotiations have resulted in five key points
Recommended Reading





