Shai-Halud Supply Chain Campaign — Vercel Response & Enhanced Protections
Vercel responded to a large-scale npm supply chain attack (Shai-Halud) affecting 40+ packages including Tinycolor, CrowdStrike, and Qix. Only a small set of 10 Vercel customer projects were impacted; affected customers were notified and provided guidance. Vercel is enhancing supply chain defenses, tightening CI/CD controls, and recommending users audit dependencies, rebuild with safe versions, and rotate tokens.
Summary
Impact to Vercel Customers
What We Did
What We’re Watching & Doing
Recommendations for Vercel Users
Timeline
References
The supply chain campaign has escalated. What began with the Qix compromise affecting ~18 core npm packages (, , , etc.) has since spread:Shai-Haludchalkdebugansi-styles
Over 40 additional packages attacked via the Tinycolor “worm” vector.
The CrowdStrike / namespace was also compromised, with multiple trojanized releases.
crowdstrike-publisherThe DuckDB maintainer account () published malicious versions matching the same wallet-drainer malware used in the Qix incidents. No Vercel customers were impacted in that DuckDB subset.
duckdb_admin
We identified Vercel customer projects whose builds depended (directly or transitively) on the compromised package versions.a small set of 10
Impacted customers have been notified and provided with project-level guidance.
In the DuckDB incident, no Vercel customer build was affected.
Working closely with npm, open-source maintainers, and ecosystem security partners to track any further spread of Shai-Halud.
Enhancing our supply chain defenses so that
deployments on Vercel remain secure by default
: stricter policies on lifecycle/postinstall scripts, lockfile hygiene, and registry validation.
Tightening internal CI/CD controls and developer tooling to catch suspicious package behavior early.
For teams using pnpm, consider enabling the new setting introduced in pnpm 10.16 to delay dependency updates (e.g., 24 hours). This helps reduce risk from compromised versions that are discovered and removed shortly after publishing.
minimumReleaseAgeAudit your dependencies (direct & transitive) to check for packages from these affected namespaces.
Rebuild with pinned safe versions and clean lockfiles ().
pnpm ciRotate any npm / GitHub / CI/CD tokens that may have been used in environments where compromised dependencies were present.
Inspect GitHub repos for unauthorized workflows or unexpected additions.
.github/workflowsEnforce least privilege (especially in automated workflows), and limit lifecycle script permissions.
September 8, 2025
— Qix / Tinycolor / core package compromise discovered.
September 9, 2025
— DuckDB issue identified.
September 15-16, 2025
— CrowdStrike / Tinycolor “worm” style propagation detected; Vercel detection expanded.
September 16, 2025
— Customer notifications, cache purges, safe rebuilds underway.
Action | Status |
Blocklisted known compromised versions from the Tinycolor, CrowdStrike, Qix, and DuckDB-affected packages | ✅ Completed |
Purged build caches for Vercel projects using those versions | ✅ Completed for impacted projects |
Coordinated safe rebuilds with clean dependencies / pinned safe versions | ✅ In progress / completed for impacted ones |
Raised platform alerting & detection thresholds for new package publishes matching the Shai-Halud indicators | ✅ Elevated monitoring active |
Source: original entry ↗
More from Vercel
Follow Vercel to get its new changes in your feed and email digest.
OpenAI Decisions API now available on AI Gateway
OpenAI's Decisions API is now accessible through Vercel's AI Gateway with an OpenAI-compatible endpoint, enabling decision models to answer typed questions and return probabilities, choices, and scores for routing, triage, and guardrails use cases. Support is available across the OpenAI SDK, AI SDK, HTTP API, and CLI with the latest versions.
Timestamp attributes now supported in Vercel Flags
Vercel Flags now supports timestamp attributes for entities, allowing you to create time-based targeting rules. Use this feature to run limited-time campaigns, show content between specific dates, or target users based on registration date.
Glyph Cluster now available in stealth on AI Gateway
Glyph Cluster, a reasoning model for coding and long-context analysis, is now available as a stealth model on Vercel's AI Gateway for Pro and Enterprise plan teams with purchased AI Gateway credits at no cost during the stealth period. The model supports function calling, streams responses, and can be accessed via AI SDK, OpenAI-compatible APIs, and coding agents.