VERCEL هجوم يغيّر قواعد اللعبة الذكاء الاصطناعي لم يعد مجرد أداة بناء — بل أصبح

Backer posted 1 min read
  1. The Attack Chain — Step by Step

A Context.ai employee was infected with Lumma Stealer back in February 2026 because he was searching for cracked Roblox scripts online.
The stealer harvested his Google Workspace credentials, along with Supabase, Datadog, and Authkit keys.
(Source: Help Net Security)

One Vercel employee was using Context.ai with his Enterprise account and had granted it “Allow All” permissions on Google Drive.
The attacker used the stolen OAuth token to access that employee’s Workspace account and pivoted directly into Vercel’s internal infrastructure.
(Source: OX Security)


  1. What Was Stolen?

The attacker exfiltrated:

  • API keys
  • GitHub tokens
  • NPM tokens
  • Internal tool logs for 580 employees

According to Vercel’s CEO, the intruder moved with unusual speed, strongly suggesting the use of AI‑accelerated reconnaissance.
(Source: Strobes)


  1. Who’s Behind It?

The group claiming responsibility: ShinyHunters — the same threat actors behind breaches at:

  • Ticketmaster
  • Santander
  • Rockstar
  • AT&T

They listed the stolen Vercel data for $2 million on BreachForums.
(Source: Strobes)


  1. The Most Dangerous Lesson

The breach was not discovered by Vercel’s security team.
It was discovered only because the attacker chose to sell the data publicly.

The time gap between initial access and detection is the most alarming part of the incident.


  1. Suggested Sections for Your Full Post
  • The Complete Hacking Series: 6 Steps — From a Roblox Script to a $2M Breach
  • Shocking Stats: 580 Employees, $2 Million, One OAuth Token
  • All Leaked Data in a Clear Grid
  • Who Are ShinyHunters? Their Criminal Track Record
  • The Most Dangerous Lesson: Detection Came From the Attacker, Not the Defenders

GitHub release
GitHub stars
GitHub forks
GitHub issues
License
Platform

More Posts

Strict Comparison in PHP Explained at the Zend Engine Level

István Döbrenteiverified - Jan 9

Supply Chain Security in PHP Projects

István Döbrenteiverified - Dec 26, 2025

Integrated Business ERP System

James Dayalverified - Apr 28, 2025

Laravel is How Development Should Be

psypher1 - Mar 31, 2025

DevLaunch - I built a Vercel-inspired dev server manager

Manthan Bhatt - Apr 8
chevron_left

Related Jobs

View all jobs →

Commenters (This Week)

1 comment
1 comment

Contribute meaningful comments to climb the leaderboard and earn badges!