Summary
Grafana Labs has disclosed that its codebase and other internal operational information were stolen after attackers gained unauthorized access to Grafana’s GitHub repositories. The breach was traced back to a token compromised during a supply chain attack targeting the TanStack open-source project. Stolen data includes source code as well as business contact names and email addresses.
The incident highlights the cascading nature of supply chain attacks in the open-source ecosystem — a compromise in one widely-used dependency (TanStack) rippled outward to compromise a downstream consumer (Grafana) that had integrated or authenticated against the affected component.
Source
Commentary
This is a textbook illustration of why software supply chain security remains one of the hardest problems in the industry. TanStack is a popular collection of open-source libraries used across thousands of projects. A single compromised token in that ecosystem gave attackers a foothold into Grafana — a company whose observability platform is deployed across critical infrastructure worldwide.
The silver lining is that Grafana disclosed quickly and transparently, which is increasingly the exception rather than the rule. But the broader lesson is uncomfortable: every organization’s security posture is only as strong as the weakest link in its dependency chain, and modern software has a lot of links.
