A Vercel employee installed the Context.ai browser extension, which was then targeted by infostealer malware (malicious software that steals credentials). The attacker used the stolen OAuth credentials — a digital permission token that grants access to systems — to walk directly into Vercel's production environment. Vercel confirmed the breach on Sunday and brought in Mandiant (a cybersecurity firm) to investigate.
The attack succeeded because OAuth grants (permission tokens issued to third-party tools) sit invisible to most security teams — they can approve access but have no way to see what's already been granted, audit who installed it, or contain the blast radius when one tool gets compromised. Vercel now defaults all environment variables to 'sensitive' status, requiring explicit review before use, to catch future misuse faster.
For developers using Vercel-hosted npm packages (software libraries downloaded millions of times weekly), the good news: audits with GitHub, Microsoft, npm, and Socket found no compromised packages or leaked code. But for security teams and developers everywhere, this reveals a widespread gap — any employee's single decision to install an AI tool becomes a potential entry point to production systems, and most security tools cannot see or block it.
Ask the AI about this article →
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
McKinsey's 2025 survey found that while 65% of companies continuously use generative AI, fewer than 5% have ac…

Anthropic launched Claude Fable 5.1 and Mythos 5.1, its most capable AI models yet, with gains in agentic codi…

John Ternus takes over as CEO of Apple today, stepping into the role as the company confronts the AI era

Top AI-native open source projects like Flue and tldraw are refusing external pull requests, often because the…

Visual Studio Code 1.135 now includes an experimental 'Rubber Duck' feature that lets developers request a sec…

Anthropic is making a permanent 25% increase to the usage limits in Claude Code, effective after September 14
