Odaily Planet Daily News According to a security alert issued by SlowMist Chief Information Security Officer @im23pds, the open source data visualization tool Grafana is suspected to have been attacked. The attacker used Gato-X to steal signing keys and invaded multiple code bases by abusing application tokens. Preliminary analysis shows that the attacker may inject JavaScript code by forging malicious branch names to steal sensitive information. The goals include using tibdex/github-app-token to generate high-privilege GitHub tokens, tampering with grafana/grafana repositories, and implanting hidden backdoors. SlowMist reminds users to remain vigilant.