logo

Vercel’s security breach started with malware disguised as Roblox cheats

ID: 39b2e2ea-072a-5f37-8bb3-1a5ce4d79681

STIX ID: report--39b2e2ea-072a-5f37-8bb3-1a5ce4d79681

Feed Name: CyberScoop

Threat Score
75/100

Date Published: 2026-04-20

Date Updated: 2026-04-21

Author: Matt Kapko

...
...

Vercel reported that an attacker, after Lumma Stealer infected a Context.ai employee, leveraged stolen OAuth tokens to take over a Vercel employee's Google Workspace and access some Vercel environments and environment variables; limited customers were impacted, indicators were published and a group claiming to be ShinyHunters is attempting to sell the stolen credentials, source code and databases while investigations continue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.