logo

Breaking: Vercel Breach Linked to Infostealer Infection at Context.ai

ID: a3710165-f390-551a-a00d-5a05f4835879

STIX ID: report--a3710165-f390-551a-a00d-5a05f4835879

Feed Name: infostealers.com

Threat Score
88/100

Date Published: 2026-04-20

Date Updated: 2026-04-28

Author: InfoStealers

...
...

**Executive Summary:** A Lumma infostealer infection on a Context.ai employee with elevated access leaked Google Workspace and developer/admin credentials (Supabase, Datadog, Authkit) which were subsequently used to pivot into Vercel; threat actor ShinyHunters is reportedly selling the stolen Vercel data. The report includes an OAuth Client ID IOC, timeline correlation to a single recorded infection, evidence of administrative Vercel access, and step-by-step remediation guidance for affected Google Workspace tenants.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.