Vulnerability  ·  2026-04-21

Vercel Supply Chain Breach via Context.ai AI Tool Compromise

VulnerabilityHigh impactGlobal
Attackers compromised Context.ai AI tool through malware disguised as Roblox cheats, then used OAuth tokens to breach Vercel employee Google Workspace accounts and access customer environment variables.
Multi-stage attack: Lumma stealer malware → Context.ai compromise → OAuth token theft → Google Workspace takeover → Vercel internal systems access.
Vercel hosting platform customers with non-sensitive environment variables; Context.ai AI Office Suite users with OAuth permissions.
Vercel advises rotating all credentials and secrets. Organizations should audit third-party AI tool OAuth permissions and implement principle of least privilege for AI service integrations.
Sources
TechCrunchCyberScoopThe Hacker News
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →