Overview
Vercel is a cloud platform specializing in frontend deployment and serverless functions, widely used by developers for hosting web applications, particularly those built with Next.js and other modern JavaScript frameworks.
Recent Developments
-
2026-07-30: Next.js lead Tim Neutkens quoted as early tester of github stacked-pull-requests public preview (2026-08-02-github-changelog-stacked-pull-requests)
-
2026-07:
skillsCLI and skills-sh ecosystem — ~25K GitHub stars; Snyk found 13.4% of community skills critical severity (2026-07-06-vercel-skills-ai-agent-package-manager) -
2026-04-19: Security breach discovered via compromised Context.ai OAuth integration (2026-04-27-vercel-security-breach)
Security Incident (April 2026)
Attack Details
- Threat Actor: ShinyHunters (cybercriminal group)
- Attack Vector: Compromised Context.ai OAuth tokens
- Root Cause: Vercel employee’s Google Workspace account used to sign up for Context.ai with broad “Allow All” OAuth permissions
- Malware: Context.ai employee device infected with Lumma Stealer via Roblox game exploit (February 2026)
- Data Accessed: Non-sensitive environment variables, API keys, internal database records
- Sale Attempt: ShinyHunters tried to sell data for $2 million on BreachForums
Vercel’s Response
- Token Revocation: All Context.ai OAuth tokens revoked platform-wide
- Security Hardening: Platform updated to default new environment variables to “sensitive” (encrypted)
- Customer Guidance: All customers advised to rotate environment variables as precaution
Impact Assessment
- Sensitive variables (encrypted at rest) were NOT compromised
- No evidence of tampering with open-source packages (Next.js)
- No evidence of production infrastructure compromise
- Small number of customers affected