INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
TanStack Attack Exposed Code Breach at Grafana Labs
| 2026-05-21 08:00 HIGH LOW DATA BREACH
Executive Summary
AI-generated
A recent data breach and extortion incident was caused by the Mini Shai-Hulud campaign, which compromised TanStack packages. The attack is attributed to TeamPCP threat actors who targeted dozens of TanStack npm packages with credential-stealing malware targeting CI/CD environments including GitHub Actions. This resulted in an unauthorized attacker downloading Grafana Labs' codebase after accessing its GitHub environment on May 17. As a result, the attackers gained access to Grafana's GitHub repositories and stole internal operational information, including business contact names and email addresses. The incident affected approximately hundreds of npm packages across multiple platforms, including OpenSearch, PyPI, GitLab, CircleCI, AWS, Google Cloud Platform, Azure, Kubernetes, HashiCorp Vault, and package registry tokens.
Technical Mitigations AI-generated
• Rotate GitHub workflow tokens immediately after discovering a compromised token.
• Implement enhanced monitoring and auditing of all commits since the May 11 incident to detect potential security breaches.
• Harden GitHub security posture by implementing additional controls, such as code reviews or access controls.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Shai-HuludShai-Hulud
Target & Sectors
Global Scope
technologytechnology
Incident Timeline
2026/05/21
Threat actors from TeamPCP compromised TanStack's CI/CD pipeline, allowing malicious packages to be presented as valid and cryptographically signed.
Click on any entity below to view its context and source!
infrastructure
2.4.6
TeamPCP also broadened its reach to compromise OpenSearch npm versions, PyPI mistralai 2.4.6, PyPI guardrails-ai 0.10.1 and further @squawk packages.
infrastructure
0.10.1
TeamPCP also broadened its reach to compromise OpenSearch npm versions, PyPI mistralai 2.4.6, PyPI guardrails-ai 0.10.1 and further @squawk packages.
Tactical Metrics
Metrics
infrastructure
2.4.6
Software Version
Click for context!
TeamPCP also broadened its reach to compromise OpenSearch npm versions, PyPI mistralai 2.4.6, PyPI guardrails-ai 0.10.1 and further @squawk packages.
Metrics
infrastructure
0.10.1
Software Version
TeamPCP also broadened its reach to compromise OpenSearch npm versions, PyPI mistralai 2.4.6, PyPI guardrails-ai 0.10.1 and further @squawk packages.
Intelligence Sources
Infosecurity-Magazine
2026-05-21
Grafana Labs Says Code Breach Stemmed from TanStack Attack
Infosecurity-Magazine
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T08:26
Comprehensive Tactical Telemetry
Highly Correlated Entities
12x
organisation
Identified Entity
the Mini
entity
2x
tactic
Cyber Operation Type
Data Breach
tactic
2x
infrastructure
Software Version
2.4.6
version
2x
timeline
Temporal Reference
May 17
date
Contextual Telemetry
Context Block
3 METRICS
malware
Malware Payload
Shai-Hulud
tool
general metric
Malicious Versions
84
malicious versions
general metric
@Tanstack/
42
@tanstack/
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.