Vercel CEO has announced the completion of a broad security investigation into a malware attack designed to steal account credentials. According to the company, the findings show the campaign was not limited to the initially reported Context.ai compromise, but extended to a wider set of targets and platforms.
Probe reviewed nearly 1 petabyte of logs
As part of the investigation, Vercel analyzed nearly 1 petabyte of network and API logs to trace the activity and understand its scope. The company said attackers distributed malware aimed at harvesting credentials across multiple services, including Vercel. Following access, the attackers were able to quickly reach non-sensitive environment variables.
Incident points to broader credential risks
A key takeaway from the update is that the attack was broader than first understood. Rather than a contained event tied only to Context.ai, the campaign appears to have targeted credentials used across developer and cloud platforms. While the disclosed access was limited to non-sensitive environment variables, the incident highlights how identity and account security remain critical attack surfaces in modern infrastructure.
Vercel expands industry coordination
In response, Vercel said it is deepening cooperation with Microsoft, AWS, and Wiz to strengthen internet security. The company has also notified affected parties and urged them to rotate credentials immediately and improve security practices. That includes reviewing access controls, updating authentication details, and hardening account and endpoint protections.
The case underscores a broader trend: malware operators continue to focus on developer ecosystems and cloud credentials as high-value entry points. For companies and developers using such platforms, prompt credential rotation, log review, and stronger account security remain essential to reducing follow-on risk.

