One employee at Vercel adopted an AI tool. One employee at that AI vendor got hit with an infostealer. That combination created a walk-in path to Vercel’s production environments through an OAuth grant that nobody had reviewed. js and its millions of weekly npm downloads, confirmed on Sunday that attackers gained unauthorized access to internal systems.
Mandiant was brought in. Law enforcement was notified. Investigations remain active.
