How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Post-incident review for TanStack npm supply chain ransom incident: No unauthorized access to customer production systems

calendar_today June 23, 2026 person Joe McManus domain grafana

On May 27, we completed our internal investigation of the recent TanStack supply chain ransom incident and confirmed our initial findings: The incident was strictly limited to Grafana Labs’ GitHub environment. There was no unauthorized access to customer production systems, and the Grafana Cloud platform was not affected. For an additional, independent audit, we engaged Mandiant, a leader in cybersecurity and incident response.

open_in_new Read original post