Attackers compromised an employee device at Context.ai, a small third-party AI tool vendor, with Lumma Stealer infostealer malware in February 2026, stealing an OAuth session token tied to a Vercel employee’s Google Workspace account. The stolen token went undetected for roughly six weeks and gave attackers persistent, MFA-bypassing access into Vercel’s internal environments, exposing credentials for a limited subset of customers along with source code and API tokens for connected services. A group using the ShinyHunters name claimed responsibility and offered the stolen data for sale.