Grafana GitHub breach stemmed from TanStack npm attack; missed token exposed repos, not customer production systems.

Grafana disclosed an unauthorized party accessed its GitHub environment and downloaded its codebase via a token.

No customer info stolen, no impact to operations, and no blackmail payment