🚨 BREAKING - Vercel got hacked!
what devs need to do RIGHT NOW 🧵
DO THIS BEFORE ANYTHING ELSE - rotate everything:
→ Mark ALL env vars as Sensitive in your Vercel dashboard
→ Revoke and regenerate GitHub tokens tied to Vercel
→ Rotate all NPM tokens
→ Rotate every API key stored as a non-sensitive env var
Rotate first. Investigate second.
VERCEL GOT HACKED
ShinyHunters - the group behind the Ticketmaster breach - is selling Vercel's internal database for $2M on BreachForums
here's why every developer should care:
- they have NPM tokens and GitHub tokens
- Vercel owns Next.js - 6 million weekly downloads
- one malicious push = global supply chain attack
- Vercel confirmed the breach today, April 19
- they literally DMed the hackers on Telegram asking them to stop
rotate your env variables RIGHT NOW