Grafana GitHub Breach Exposes Source Code via TanStack npm Attack

2026-05-20T07:24:07Z91bd783d357ffa674e0a13871d117f9bd75e0285dd17cc1a82bbeaf007268672
antvcode-exfiltrationcredential-theftcve-2026-31635cve-2026-42945cve-2026-8043dirtydecryptextortiongithubgithub-actionsgrafanaivantilinux-kernelmini-plasma','windows-zero-day','trapdoor','android','ad-fraud'mini-shai-huludnginxnpmnx-consoleprivilege-escalationrceseppmailsupply-chain-attacktanstackteampcpvs-code-extension

What happened

A wave of high-impact supply‑chain compromises and active exploits was reported between May 15–20, 2026. Key incidents include a Grafana GitHub token breach tied to a TanStack/npm supply‑chain attack (codebase download and extortion), GitHub investigating an alleged TeamPCP compromise of ~4,000 internal repos, and Mini Shai‑Hulud/AntV npm package compromises and malicious GitHub Actions/Nx Console artifacts that steal CI/dev credentials. Multiple high‑risk vulnerabilities and exploits are in play: a DirtyDecrypt PoC for the Linux kernel LPE (CVE‑2026‑31635), NGINX heap overflow (CVE‑2026‑42945

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
91bd783d357ffa674e0a13871d117f9bd75e0285dd17cc1a82bbeaf007268672
Enrichment time
2026-05-20T07:24:07Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.