Grafana Labs disclosed on May 16, 2026, that a threat actor infiltrated its GitHub environment by exploiting a misconfigured CI/CD pipeline, stealing a privileged token, downloading the company’s private codebase, and then attempting extortion. The company refused to pay the ransom, citing FBI guidance that payment only incentivizes further criminal activity.

The root cause was traced to a recently enabled GitHub Action containing a “Pwn Request” vulnerability — a misconfiguration in a workflow triggered on pull_request_target events that inadvertently granted external contributors access to production secrets during CI runs. The attacker forked a Grafana repository, injected malicious code via a curl command to dump environment variables, encrypted the exfiltrated data with a private key, then deleted the fork to cover their tracks. The compromised credentials were then used to replicate the attack against four additional private repositories.

Grafana’s security team detected the breach when one of its deployed canary tokens was triggered. They immediately invalidated compromised credentials, removed the vulnerable GitHub Action, and disabled all workflows across public repositories. The company confirmed that no customer data or personal information was accessed during the incident.

Source

Cryptika Cybersecurity — Grafana Labs Security Breach

Commentary

The irony of an observability company getting blindsided by a breach in its own infrastructure wasn’t lost on the community — but credit where it’s due, Grafana’s response was textbook: canary tokens caught it fast, credentials were rotated immediately, and they went public within a day. That’s better incident response than most companies manage.

The real story here is the attack vector. The pull_request_target misconfiguration is a widely underestimated attack surface across the entire open-source ecosystem. Any project that runs CI workflows with access to secrets on external PRs is potentially vulnerable. If your organization uses GitHub Actions, audit your workflows for pull_request_target triggers immediately — this is the kind of supply chain risk that scales across thousands of projects.

By Allan