Vercel breach via Context.ai OAuth exposes credentials

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Vercel disclosed a breach that gave attackers unauthorized access to internal systems after a compromised Context.ai account was used to hijack a Vercel employee’s Google Workspace credentials.
- Context.ai was identified as the initial foothold, with its OAuth token granting “Allow All” permissions that let the attacker pivot into Vercel’s environment and non‑sensitive environment variables.
- ShinyHunters claimed responsibility for the breach, offering the stolen data for a $2 million price tag, though Google Threat Intelligence suggests the claim may be a fake.
- Hudson Rock reported that a Context.ai employee was infected with Lumma Stealer in February 2026, harvesting Google Workspace, Supabase, Datadog, and Authkit credentials that facilitated the supply‑chain escalation.
- Vercel responded by notifying affected customers, urging credential rotation, and rolling out new dashboard features that default environment variables to “sensitive” and improve management.
- Google removed a malicious Context.ai Chrome extension from the Web Store on March 27 2026, which had embedded an OAuth grant allowing read access to users’ Google Drive files.
- Nudge Security highlighted that the breach underscores a broader pattern where attackers exploit OAuth tokens from small AI SaaS vendors to gain lateral movement across downstream enterprises.
Why it matters: Customers whose credentials were compromised risk unauthorized access to their Vercel projects, while Vercel must address reputational fallout and tighten OAuth token controls; the incident highlights how a single third‑party AI tool can become a high‑value entry point for supply‑chain attacks across cloud services.



