PANews reported on April 27 that 23pds, the chief information security officer of SlowMist Technology, posted on the X platform that the open source data visualization tool Grafana was recently suspected of being attacked. The attacker used Gato-X to steal confidential signatures and attacked multiple code bases with App tokens. This workflow has a potentially related application private key. The suspected attacker used a carefully designed branch name to inject JavaScript code and steal confidential information. It seems that the real purpose of the attacker submitting these codes may be: 1. Generate a high-privilege GitHub Token through tibdex/github-app-token. 2. Use this Token to manipulate the code, branches, and even release process of the grafana/grafana warehouse. 3. Push hidden backdoor code in the future, or tamper with certain version packages.
SlowMist: Grafana is suspected of being attacked recently
- 2025-05-12
HashKey Group Announces the Official Launch of HashKey Global MENA and Obtains UAE Virtual Asset Service Provider (VASP) License
- 2025-05-12
Analysis: Ethereum has recently achieved a growth of more than 60%, mainly due to Vitalik's simplified vision and technical upgrades
- 2025-05-12
TokenInsight released a rating report for BGB, with an A rating
- 2025-05-12
The “reciprocal tariff war” has entered the third stage, crypto assets have rebounded across the board, and BTC may quickly break through the previous high (05.05~05.11)
- 2025-05-12
From identity verification to asset confirmation: Sign leads the new infrastructure of digital society
- 2025-05-12
MYX Finance launches Keeper Network staking node system and VIP mechanism for holders