Business

Vercel Day Six Still Silent as Push Security Traces the Breach to a Roblox Cheat Infostealer

Vercel status-page dashboard at full screen, all systems green, no incidents listed.
New Grok Times
TL;DR

Six days after the OAuth-token breach, Vercel's bulletin still reads no update — while Push Security walks the supply chain from a Roblox-cheat infection through Context.ai into a $2M ransom demand.

MSM Perspective

Push Security and SpecterOps published the technical reconstruction; mainstream business desks have allocated bandwidth to the Cursor-SpaceX deal, not Vercel's silence.

X Perspective

Security X is now treating the Vercel breach as the canonical supply-chain-via-OAuth case, with Roblox-cheat infostealers named as the entry vector.

Six days after Vercel disclosed an April 18-19 security incident, the company's status page still shows green and its bulletin has not been updated since the disclosure week. The paper's Friday Day 6 read framed the silence as Cursor-deal-absorbed; Saturday extends that frame, with one substantive addition. Push Security's April 23 writeup — and a follow-up by SpecterOps — reconstructed the attack path: a Vercel employee at downstream SaaS provider Context.ai installed Roblox auto-farm cheats containing the Lumma infostealer; browser credentials, Supabase keys, Datadog tokens, and Authkit credentials were exfiltrated; an attacker used a stolen OAuth token to enter Vercel's Google Workspace, then moved laterally into customer environment-variable stores. [1][2]

That sequence is now the canonical supply-chain-via-OAuth case study. The threat actor, claiming the ShinyHunters identity, posted samples on BreachForums and demanded $2 million in Bitcoin. [3] Vercel has confirmed the third-party AI tool vector but has not named Context.ai in its own communications.

Day 6 of silence is the operational artifact. Customers learning from third-party security researchers what their own platform's incident was — while the platform's bulletin holds at "no updates" — is not how disclosure cycles in 2024 ran. The architecture has changed because the attack path has changed: BYOD developer machines, OAuth grants the security team never saw, and a sub-vendor whose Roblox download became a $2 million ransom demand. The platform layer is the bystander.

-- THEO KAPLAN, San Francisco

Get the New Grok Times in your inbox

A weekly digest of the stories shaping the timeline — delivered every edition.

No spam. Unsubscribe anytime.