INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

TanStack Attack Exposed Code Breach at Grafana Labs

| 2026-05-21 08:00 HIGH LOW DATA BREACH
Executive Summary
AI-generated
A recent data breach and extortion incident was caused by the Mini Shai-Hulud campaign, which compromised TanStack packages on May 11. TeamPCP threat actors targeted dozens of TanStack npm packages with credential-stealing malware targeting CI/CD environments including GitHub Actions, resulting in at least one unauthorized attacker downloading Grafana Labs' codebase after accessing its GitHub environment. The attack works by compromising the supply chain and bypassing security filters through cryptographically signed malicious packages presented as valid to downstream developers. As of May 21, Grafana Labs has taken mitigation efforts, including rotating automation tokens, implementing enhanced monitoring, auditing all commits since the incident, and hardening its GitHub security posture, with no indication that customer production systems or operations have been compromised.
Technical Mitigations AI-generated
• Rotate GitHub workflow tokens immediately after discovering a compromised repository. • Implement enhanced monitoring and auditing of all commits since the May 11 incident to detect potential security breaches. • Harden GitHub security posture by implementing additional security measures, such as two-factor authentication or access controls.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Shai-HuludShai-Hulud
Target & Sectors
Global Scope technologytechnology
Incident Timeline
‎2026/05/21
Threat actors from TeamPCP compromised TanStack's CI/CD pipeline, allowing malicious packages to be presented as valid and cryptographically signed.
infrastructure 2.4.6
infrastructure 0.10.1
Tactical Metrics
Metrics
infrastructure
‎2.4.6
Software Version
Metrics
infrastructure
‎0.10.1
Software Version
Intelligence Sources
Infosecurity-Magazine 2026-05-21