App Host Vercel Was Hacked Through a Third-Party AI Tool

Vercel's popular React framework Next.js was not affected by the breach, but access keys and source code may have leaked.

Key Takeaways

  • A breach of cloud hosting platform Vercel stemmed from a compromised app made by Context AI, which was connected to an employee’s account.
  • Credentials for “a limited subset of customers” were compromised.
  • A hacker claims to be selling the data, which allegedly contains access keys, source code, and database information.

Cloud hosting platform Vercel has just revealed a big internal data breach.

The security incident stemmed from a breach in a third-party AI tool’s Google Workspace OAuth application, which threat actors used to access an employee’s Workspace account.

The company has confirmed that its popular open-source projects, including Next.js and Turbopack, remain secure.

What to Know About the Breach

The breach was due to an app made by Context AI, Vercel says, which one employee downloaded and connected to their corporate account.

In its statement about the incident, Vercel said that the credentials for “a limited subset of customers” were compromised. Anyone who hasn’t already been contacted was not in that group, they say.

 

About Tech.co Video Thumbnail Showing Lead Writer Conor Cawley Smiling Next to Tech.co LogoThis just in! View
the top business tech deals for 2026 👨‍💻
See the list button

Vercel has “deployed extensive protection measures and monitoring,” the company added.

A Hacker Claims to Be Selling Breached Data

There’s more to the story: A threat actor calling themself “ShinyHunters” has taken credit for breaching Vercel in a hacking forum, Bleeping Computer reports.

The hacker also claims to be selling the stolen data, which reportedly includes:

  • Access keys
  • Source code
  • Database data
  • Internal deployments
  • API keys

The forum post further explains that, “the access I’m about to give you includes multiple employee accounts with access to several internal deployments, API keys (including some NPM tokens and some GitHub tokens).”

These claims haven’t been verified, however, so we don’t know for sure how much of what the hacker is saying is true.

Supply Chain Hacks on the Rise

The incident is an example of the growth of a type of hack that targets software developers that provide commonly used code. In this case, Vercel is behind the popular React framework Next.js.

Granted, this framework wasn’t impacted in this particular hack, but if successfully compromised, the software could open up a broad range of targets for hackers hoping to access data at scale. After all, the Vercel breach emerged through a breach at Context AI.

CEO Guillermo Rauch addressed the incident on his personal social media account, saying that “my advice to everyone is to follow the best practices of security response: secret rotation, monitoring access to your Vercel environments and linked services, and ensuring the proper use of the sensitive env variables feature.”

We’ve previously reported on a study that found one in four data breaches are due to exploits of third-party apps. Looks like we can now add one more example to the list.

Did you find this article helpful? Click on one of the following buttons
We're so happy you liked! Get more delivered to your inbox just like it.

We're sorry this article didn't help you today – we welcome feedback, so if there's any way you feel we could improve our content, please email us at contact@tech.co

Written by:
Adam has been a writer at Tech.co for nine years, covering fleet management and logistics. He has also worked at the logistics newletter Inside Lane, and has worked as a tech writer, blogger and copy editor for more than a decade. He was a Forbes Contributor on the publishing industry, for which he was named a Digital Book World 2018 award finalist. His work has appeared in publications including Popular Mechanics and IDG Connect, and his art history book on 1970s sci-fi, 'Worlds Beyond Time,' was a 2024 Locus Awards finalist. When not working on his next art collection, he's tracking the latest news on VPNs, POS systems, and the future of tech.
Explore More See all news
Back to top