Grafana Labs security update: Latest on TanStack npm supply chain ransomware incident
Updated on June 1, 2026: Our internal investigation is complete, and it confirms our initial findings that there was no unauthorized access to customer production systems or the Grafana Cloud platform. We have engaged Mandiant, a leader in cybersecurity and incident response, to perform an additional audit, and expect its post-incident report to be completed in June. As part of our standard security practices, we will share in the coming weeks additional information from our post-incident review
