Grafana Investigating Token Compromise and Extortion Attempt
An "unauthorized party” obtained a token with access to the Grafana Labs GitHub environment and downloaded Grafana’s codebase.
All topics
An "unauthorized party” obtained a token with access to the Grafana Labs GitHub environment and downloaded Grafana’s codebase.
Yet another supply chain attack has hit the open source ecosystem, this time impacting the Checkmarx KICS Docker Hub repository.
GitHub said the changes will help "fortify the security of the software supply chain" after a recent surge of attacks targeting the npm ecosystem.
The affected packages include Chalk and Debug, and one of the contributors to those packages said the compromise was the result of him clicking on a phishing email related to setting up 2FA on his account.