The Chief Information Security Officer of Slow Fog Technology, 23pds, stated in a post on the X platform that the open source data visualization tool Grafana has recently been suspected of being attacked. The attacker used Gato-X to steal confidential signatures and attacked multiple code repositories using app tokens. This workflow has a potentially relevant application private key, and the suspected attacker used a carefully crafted branch name to inject JavaScript code and steal confidential information.
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
The Chief Information Security Officer of Slow Fog Technology, 23pds, stated in a post on the X platform that the open source data visualization tool Grafana has recently been suspected of being attacked. The attacker used Gato-X to steal confidential signatures and attacked multiple code repositories using app tokens. This workflow has a potentially relevant application private key, and the suspected attacker used a carefully crafted branch name to inject JavaScript code and steal confidential information.