Grafana Labs Confirms GitHub Ransomware Attack; Customer Systems Unaffected

iconKuCoinFlash
Share
Share IconShare IconShare IconShare IconShare IconShare IconCopy
AI summary iconSummary

expand icon
Grafana Labs confirmed a GitHub ransomware attack, potentially involving a Sybil attack vector, after attackers gained access to internal repositories through a TanStack npm supply chain compromise. The breach occurred on May 16, followed by a ransom demand after unauthorized code downloads. No customer systems or Grafana Cloud were impacted, and the code remained unchanged. The stolen data may include internal operations and contact details, but no production data was compromised. The company declined to pay the ransom and is cooperating with authorities. Security enhancements include token rotation and CI/CD hardening. A reentrancy attack was not confirmed in this incident.

BlockBeats report: On May 20, Grafana Labs released a security update stating that on May 16, the company confirmed a targeted cyberattack in which attackers gained unauthorized access to its codebase via a GitHub repository and subsequently made a ransom demand.


The company stated that the incident originated from an attack targeting the TanStack npm supply chain; after gaining initial access, the attackers exploited a forgotten GitHub workflow token to successfully infiltrate the company’s internal repository environment.


Grafana Labs emphasized that the investigation has found no impact on customer production systems or the Grafana Cloud platform; the incident was limited to the company’s GitHub environment, including source code and some internal collaboration repositories, with no code alterations detected.


The company stated that the downloaded data, in addition to the source code, may include internal operational information and names and email addresses of business contacts, but does not involve production system data.


The attackers then demanded a ransom to prevent the code from being leaked, but Grafana Labs stated that it refused to pay and has collaborated with law enforcement on the investigation.


The company has implemented a series of security measures, including rotating automated tokens, enhancing monitoring, auditing submission logs, and strengthening CI/CD security, and has stated that a full post-incident report will be released.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.