A fresh cybersecurity storm has erupted around Vercel after a third-party artificial intelligence tool linked to the company was compromised, exposing sensitive configuration data and raising fears of a far-reaching software supply chain attack.
In an advisory tagged NCA-220426-01, Nigeria’s Computer Emergency Readiness and Response Team, CERRT.NG, warned that the breach could have devastating implications for organizations relying on Vercel’s cloud hosting and deployment infrastructure.
According to the advisory, the incident stemmed from the compromise of an external AI tool known as Context AI, which reportedly gave attackers unauthorized access to internal systems and sensitive data, including credentials and environment variables.
“The incident resulted in unauthorized access to internal systems and exposure of sensitive configuration data, including credentials and environment variables,” the advisory stated.
Cybersecurity experts fear the breach could open the door to stealth attacks capable of infecting legitimate applications with malicious code, potentially spreading compromised software to unsuspecting users across the globe.
CERRT.NG warned that exposed environment variables such as API keys, authentication tokens and database credentials could allow cybercriminals to infiltrate critical systems, steal sensitive information and maintain hidden access for extended periods.
“Attackers could potentially inject malicious code into legitimate applications, leading to widespread distribution of compromised software to end users,” the agency cautioned.
The advisory further noted that because platforms like Vercel are deeply trusted within the software development ecosystem, such compromises could remain undetected for long periods while attackers quietly exfiltrate data and expand their foothold.
Analysts say the incident underscores growing concerns over third-party AI integrations and the mounting risks associated with software supply chain vulnerabilities, especially as businesses increasingly depend on automated cloud deployment tools.
The affected systems listed in the advisory include the Vercel hosting platform itself, applications and services deployed through the platform, as well as integrated third-party services connected through exposed environment variables.
To mitigate the risks, CERRT.NG urged organizations to immediately apply the latest Microsoft security updates, ensure Microsoft Defender components are fully updated, restrict local access to critical infrastructure and enforce strict least-privilege access controls.
The agency also stressed the need for stronger phishing defenses and heightened cybersecurity awareness among users to reduce the chances of initial compromise.
Industry reports linked in the advisory indicate that the breach may have been connected to an infostealer malware infection at Context AI, intensifying fears that attackers exploited compromised developer environments to gain access to sensitive infrastructure.
Additional details on the incident were published by The Hacker News and cybersecurity monitoring platform Infostealers.com.