Grafana Labs reports that attackers steal its source code after compromising access to its GitHub environment. According to the company, the breach stems from a stolen access token, which the hackers use to obtain unauthorized entry. Grafana says the incident leads to downloads of its codebase from GitHub, indicating that the attackers successfully exfiltrate source materials.
Both outlets describe Grafana’s disclosure as a confirmation of unauthorized access and source-code theft, tied directly to the GitHub token compromise. The reports present the core sequence of events: Grafana detects or discloses the breach, attributes it to the misuse of a stolen GitHub token, and states that the resulting activity includes the download of its codebase.
The disclosures emphasize the role of credentials in the attack chain and the impact on access to proprietary source. The reports do not specify additional technical details such as the scope of the data beyond the source code, or whether any further systems were compromised.