Vercel OAuth Supply Chain Attack

DSCI pdf 2026-04-15T00:00:00

Abstract

An OAuth-based supply chain attack via Lumma Stealer at Context.ai compromised Google Workspace OAuth tokens, leading to unauthorized access to Vercel's internal systems and exposure of non-sensitive environment variables, highlighting weaknesses in OAuth trust relationships and SaaS data protection practices.

Loading executive summary...
Loading full markdown...

Your browser does not support inline PDF viewing.

Download the PDF to view it.

Match Rate: 10.00/10 (Relevance to core cybersecurity goals)

LINK COPIED TO CLIPBOARD