Vercel Hack: Why You Need to Rotate Your "Non-Sensitive" Environment Variables Today

TL;DR AI
2 min readKey summary
Vercel said an unauthorized actor got into internal systems through a compromised third-party AI tool linked to Google Workspace OAuth.
Sensitive environment variables remained encrypted, but some non-sensitive variables may have been exposed.
Users should audit projects and rotate any affected credentials, including keys for GitHub, AWS, Supabase, and Stripe.
A group calling itself ShinyHunters claims it is selling the data.

