Grafana Labs says a recent data breach originates from the TanStack supply chain attack. According to the company, the incident is tied to access gained through compromised credentials connected to the TanStack vector. SecurityWeek reports that hackers reached Grafana’s GitHub repositories and that the attacker obtained a token that was not rotated after it was compromised, which enabled the continued access. The outlet adds that, through this access, attackers obtained Grafana’s codebase and other data. Infosecurity Magazine likewise reports that Grafana Labs confirms the breach stemmed from the TanStack attack, aligning with the broader attribution to the supply-chain compromise.

Across the two reports, the key points are that the breach is linked to the TanStack incident, that the mechanism involves an exposed or compromised token, and that the access affected Grafana’s GitHub code repositories as well as additional data. Both accounts describe attribution to the earlier supply-chain compromise rather than a separate, unrelated intrusion.