Tools
In collaboration with @github, @Microsoft, @npmjs, and @SocketSecurity, our security team has confirmed that no npm packages published by Ve…
In collaboration with @github, @Microsoft, @npmjs, and @SocketSecurity, our security team has confirmed that no npm packages published by Vercel have been compromised. There is no evidence of tamperin
In collaboration with @github, @Microsoft, @npmjs, and @SocketSecurity, our security team has confirmed that no npm packages published by Vercel have been compromised. There is no evidence of tampering, and we believe the supply chain remains safe. https://vercel.com/kb/bulletin/vercel-april-2026-security-incident
Related
- Our investigation is ongoing. In the meantime, we have updated the security bulletin with best practices you can follow for peace of mind: h…
- We’ve identified a security incident that involved unauthorized access to certain internal Vercel systems, impacting a limited subset of cus…
- Our investigation has revealed that the incident originated from a third-party AI tool with hundreds of users whose Google Workspace OAuth a…
- Additional security bulletin updates include: • Clarification that account and project deletion do not eliminate environment variable risk •…
Source: Vercel (X) | 2026-04-21