According to PANews, a potential security breach has been reported involving the open-source data visualization tool Grafana. The Chief Information Security Officer of SlowMist Technology, known as 23pds, shared on the X platform that attackers may have used the Gato-X exploit to steal confidential signatures and attack multiple code repositories using app tokens.
The workflow in question reportedly involves a possibly related application private key. The suspected attackers allegedly used carefully crafted branch names to inject JavaScript code and steal sensitive information. The primary objectives of these code submissions appear to be generating high-privilege GitHub tokens via tibdex/github-app-token, manipulating the code, branches, and even the release process of the grafana/grafana repository, and potentially pushing concealed backdoor codes or tampering with certain version packages in the future.