Grafana Investigating Token Compromise and Extortion Attempt
An "unauthorized party” obtained a token with access to the Grafana Labs GitHub environment and downloaded Grafana’s codebase.

An "unauthorized party” obtained a token with access to the Grafana Labs GitHub environment and downloaded Grafana’s codebase.
May 20, 2026 | 2 min read

UPDATE -- Grafana, a popular open-source analytics and visualization platform, on Saturday said that it discovered “an unauthorized party” had obtained a token with access to the Grafana Labs GitHub environment. Grafana said the threat actors had stolen source code, and in an updated advisory on Tuesday it said they also accessed GitHub repositories that some Grafana Labs teams use to collaborate on and store internal operational information and other details about the business (including business contact names and email addresses).
Grafana on Tuesday also determined that the incident had stemmed from a supply chain attack on TanStack npm via the Mini Shai-Hulud campaign. TanStack, a collection of open-source libraries related to web development tasks, said it was hit on May 11 by an attacker that published 84 malicious versions across 42 npm packages. On Grafana's end, the malicious activity was first detected on May 11 (threat actors extorted Grafana on May 16).
"To date, the investigation has found no evidence that customer production systems or operations have been compromised," according to Grafana on Tuesday. "This incident was strictly limited to the Grafana Labs GitHub environment and did not affect our production systems or the Grafana Cloud platform."
Grafana is used to monitor, analyze, and display data in real time, and is especially popular in IT, DevOps, and data engineering for tracking system performance, application metrics, and business data. Grafana Labs hosts and maintains its open-source software projects – including Grafana OSS, Grafana Loki, Grafana OnCall, and more – in its public GitHub space.
The unnamed threat actor was able to download Grafana’s codebase, according to Grafana in a series of Twitter posts.

“Our investigation has determined that no customer data or personal information was accessed during this incident, and we have found no evidence of impact to customer systems or operations,” according to Grafana.
Grafana said it has since initiated forensic analysis measures and has likely identified the source of the credential leak. It has invalidated the compromised credentials. However, Grafana didn’t share details about how the token was acquired, or the timeline of the compromise. It said it will share further information in a more detailed post-incident review, after the full investigation is complete.
Grafana also said it refused to pay a ransom after the threat actor attempted to extort it by demanding a payment in exchange for not releasing its codebase.
“Based on our operational experience and the published stance of the FBI, which notes that ‘paying a ransom doesn't guarantee you or your organization will get any data back’ and only ‘offers an incentive for others to get involved in this type of illegal activity,’ we’ve determined the appropriate path forward is to not pay the ransom,” according to Grafana.
Open source tools and platforms continue to be a major target for threat actors in recent months, and May saw multiple major open-source and software supply-chain attacks targeting developer ecosystems and CI/CD infrastructure. Just this past week, the “Mini Shai-Hulud” campaign compromised npm and PyPI packages tied to TanStack, Mistral AI, and OpenSearch, stealing GitHub and cloud credentials.
This article was updated on May 20 with new updates from Grafana about the incident.
May 20, 2026 | 2 min read
Lindsey O’Donnell-Welch is an award-winning journalist who strives to shed light on how security issues impact not only businesses and defenders on the front line, but also the daily lives of consumers.