Overview

Vercel is a cloud platform specializing in frontend deployment and serverless functions, widely used by developers for hosting web applications, particularly those built with Next.js and other modern JavaScript frameworks.

Recent Developments

Security Incident (April 2026)

Attack Details

  • Threat Actor: ShinyHunters (cybercriminal group)
  • Attack Vector: Compromised Context.ai OAuth tokens
  • Root Cause: Vercel employee’s Google Workspace account used to sign up for Context.ai with broad “Allow All” OAuth permissions
  • Malware: Context.ai employee device infected with Lumma Stealer via Roblox game exploit (February 2026)
  • Data Accessed: Non-sensitive environment variables, API keys, internal database records
  • Sale Attempt: ShinyHunters tried to sell data for $2 million on BreachForums

Vercel’s Response

  1. Token Revocation: All Context.ai OAuth tokens revoked platform-wide
  2. Security Hardening: Platform updated to default new environment variables to “sensitive” (encrypted)
  3. Customer Guidance: All customers advised to rotate environment variables as precaution

Impact Assessment

  • Sensitive variables (encrypted at rest) were NOT compromised
  • No evidence of tampering with open-source packages (Next.js)
  • No evidence of production infrastructure compromise
  • Small number of customers affected

Sources