INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

TanStack Attack Exposed Code Breach at Grafana Labs

| 2026-05-21 08:00 HIGH LOW DATA BREACH
Executive Summary
AI-generated
A recent data breach and extortion incident was caused by the Mini Shai-Hulud campaign, which compromised TanStack packages. The attack is attributed to TeamPCP threat actors who targeted dozens of TanStack npm packages with credential-stealing malware targeting CI/CD environments including GitHub Actions. This resulted in an unauthorized attacker downloading Grafana Labs' codebase after accessing its GitHub environment on May 17. As a result, the attackers gained access to Grafana's GitHub repositories and stole internal operational information, including business contact names and email addresses. The incident affected approximately hundreds of npm packages across multiple platforms, including OpenSearch, PyPI, GitLab, CircleCI, AWS, Google Cloud Platform, Azure, Kubernetes, HashiCorp Vault, and package registry tokens.
Technical Mitigations AI-generated
• Rotate GitHub workflow tokens immediately after discovering a compromised token. • Implement enhanced monitoring and auditing of all commits since the May 11 incident to detect potential security breaches. • Harden GitHub security posture by implementing additional controls, such as code reviews or access controls.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Shai-HuludShai-Hulud
Target & Sectors
Global Scope technologytechnology
Incident Timeline
‎2026/05/21
Threat actors from TeamPCP compromised TanStack's CI/CD pipeline, allowing malicious packages to be presented as valid and cryptographically signed.
infrastructure 2.4.6
infrastructure 0.10.1
Tactical Metrics
Metrics
infrastructure
‎2.4.6
Software Version
Metrics
infrastructure
‎0.10.1
Software Version
Intelligence Sources
Infosecurity-Magazine 2026-05-21