Grafana Labs disclosed that a targeted attack tied to the Mini Shai-Hulud npm worm and a poisoned TanStack package led to source code theft and a ransom demand, but its production environments and Grafana Cloud infrastructure were not affected. The company said the attackers only achieved read-only access to GitHub repositories and business contact data, while Grafana has since rotated tokens and hardened its development security controls. #GrafanaLabs #MiniShaiHulud #TanStack
Keypoints
- The intrusion started when a developer pipeline ingested a poisoned upstream npm package on May 11, 2026.
- Grafana Labs traced the attack to the Mini Shai-Hulud npm worm campaign.
- A missed GitHub workflow token allowed attackers to access and clone company repositories.
- The attackers demanded ransom on May 16, 2026, but Grafana Labs refused to negotiate.
- No production systems or Grafana Cloud environments were compromised, and the codebase was not altered.
Read More: https://securityonline.info/grafana-labs-source-code-theft-mini-shai-hulud-npm-worm/