Grafana GitHub Breach Exposes Source Code via TanStack npm Attack
2026-05-20T07:24:07Z•91bd783d357ffa674e0a13871d117f9bd75e0285dd17cc1a82bbeaf007268672
antvcode-exfiltrationcredential-theftcve-2026-31635cve-2026-42945cve-2026-8043dirtydecryptextortiongithubgithub-actionsgrafanaivantilinux-kernelmini-plasma','windows-zero-day','trapdoor','android','ad-fraud'mini-shai-huludnginxnpmnx-consoleprivilege-escalationrceseppmailsupply-chain-attacktanstackteampcpvs-code-extension
What happened
A wave of high-impact supply‑chain compromises and active exploits was reported between May 15–20, 2026. Key incidents include a Grafana GitHub token breach tied to a TanStack/npm supply‑chain attack (codebase download and extortion), GitHub investigating an alleged TeamPCP compromise of ~4,000 internal repos, and Mini Shai‑Hulud/AntV npm package compromises and malicious GitHub Actions/Nx Console artifacts that steal CI/dev credentials. Multiple high‑risk vulnerabilities and exploits are in play: a DirtyDecrypt PoC for the Linux kernel LPE (CVE‑2026‑31635), NGINX heap overflow (CVE‑2026‑42945
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 91bd783d357ffa674e0a13871d117f9bd75e0285dd17cc1a82bbeaf007268672
- Enrichment time
- 2026-05-20T07:24:07Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.