Wu Shuo learned that, according to an official post from Vercel, their security team, after joint investigation with GitHub, Microsoft, npmjs, and SocketSecurity, confirmed that no npm packages published by Vercel have been compromised in recent security incidents. Vercel stated that currently, there is no evidence of tampering, and their software supply chain remains secure. It is reported that on April 19, Vercel confirmed that its internal systems were accessed without authorization. The cause was that an attacker gained access by infiltrating a third-party AI tool (Context AI) used by an employee of the platform through Google Workspace OAuth credentials, obtaining some non-sensitive environment variables, but sensitive data was not affected.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin