Signal

GitHub and Grafana Labs confirm source code breaches linked to threat actor TeamPCP

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-05-18 17:50 UTCUpdated 2026-05-20 04:01 UTC
rss
cvebreachthreat_actorsecurity_toolingincident_response
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (2 domains)domains are deduped. counts indicate coverage, not truth.
2 top sources shown
Grafana Labs Confirms Hackers Stole Source Code
Infosecurity Magazine · News · infosecurity-magazine.com · 2026-05-19 09:15 UTC
limited source diversity in top sources
Overview

GitHub is investigating unauthorized access to approximately 4,000 internal repositories after threat actor TeamPCP listed the platform's source code and internal organizations for sale on a cybercrime forum. Meanwhile, Grafana Labs confirmed that hackers stole its codebase via a GitHub breach.

Entities
GitHubGrafana LabsTeamPCP
Score total
0.96
Momentum 24h
2
Posts
2
Origins
2
Source types
1
Duplicate ratio
0%
Why now
  • The incidents were disclosed within the last 24 hours, indicating ongoing investigations.
  • TeamPCP's public listing of stolen code has raised immediate security concerns.
  • Grafana Labs' confirmation links the breach to a major open source tool provider, amplifying impact.
Why it matters
  • Source code breaches can expose proprietary technology and increase risk of further attacks.
  • Threat actor TeamPCP's sale of internal repositories highlights the monetization of stolen code.
  • GitHub's internal breach impacts multiple organizations relying on its platform for code hosting.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: medium
Recurring claims
  • GitHub is investigating unauthorized access to approximately 4,000 internal repositories linked to threat actor TeamPCP.
  • Grafana Labs confirmed hackers stole its source code via a GitHub breach.
How sources frame it
  • GitHub: neutral
  • Grafana Labs: neutral
All evidence
All evidence
GitHub Investigating TeamPCP Claimed Breach of ~4,000 Internal Repositories
thehackernews · thehackernews.com · 2026-05-20 04:01 UTC
Grafana Labs Confirms Hackers Stole Source Code
Infosecurity Magazine · infosecurity-magazine.com · 2026-05-19 09:15 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 2Origin domains: 2Duplicates: -
Showing 2 / 0
Top publishers (this list)
  • thehackernews (1)
  • Infosecurity Magazine (1)
Top origin domains (this list)
  • thehackernews.com (1)
  • infosecurity-magazine.com (1)