logo

Hacker Active Well Beyond Context.ai Compromise, Says Vercel CEO

ID: 05e20d64-2963-522f-8ff2-980dd5a1e678

STIX ID: report--05e20d64-2963-522f-8ff2-980dd5a1e678

Feed Name: The Cyber Express

Threat Score
70/100

Date Published: 2026-04-23

Date Updated: 2026-04-23

Author: Mihir Bagwe

...
...

**Executive summary:** Vercel disclosed that a threat actor distributed malware (Lumma Stealer) and used social engineering to steal tokens and keys from developer machines, resulting in unauthorized API usage and enumeration of non-sensitive environment variables across multiple customer accounts; the company identified additional accounts with prior independent compromise, has notified affected customers, and confirmed no evidence of tampering of Vercel-published npm packages.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.