Vercel, a cloud deployment and hosting platform, experienced a security breach due to an OAuth supply chain attack. The attack, which began with a Lumma Stealer malware infection at a third-party vendor, allowed the attacker to access Vercel's internal systems and enumerate customer project environment variables. The breach highlights the risks associated with OAuth trust relationships and platform environment variables. The incident is still under investigation, and key details, including the full scope of downstream impact and attribution, may evolve as more information becomes available.