megachangelog
Security

Shai-Halud Supply Chain Campaign — Vercel Response & Enhanced Protections

Vercel responded to a large-scale npm supply chain attack (Shai-Halud) affecting 40+ packages including Tinycolor, CrowdStrike, and Qix. Only a small set of 10 Vercel customer projects were impacted; affected customers were notified and provided guidance. Vercel is enhancing supply chain defenses, tightening CI/CD controls, and recommending users audit dependencies, rebuild with safe versions, and rotate tokens.

Summary

Impact to Vercel Customers

What We Did

What We’re Watching & Doing

Recommendations for Vercel Users

Timeline

References

The supply chain campaign has escalated. What began with the Qix compromise affecting ~18 core npm packages (, , , etc.) has since spread:Shai-Haludchalkdebugansi-styles

Read more

  • Over 40 additional packages attacked via the Tinycolor “worm” vector.

  • The CrowdStrike / namespace was also compromised, with multiple trojanized releases.crowdstrike-publisher

  • The DuckDB maintainer account () published malicious versions matching the same wallet-drainer malware used in the Qix incidents. No Vercel customers were impacted in that DuckDB subset.duckdb_admin

  • We identified Vercel customer projects whose builds depended (directly or transitively) on the compromised package versions.a small set of 10

  • Impacted customers have been notified and provided with project-level guidance.

  • In the DuckDB incident, no Vercel customer build was affected.

  • Working closely with npm, open-source maintainers, and ecosystem security partners to track any further spread of Shai-Halud.

  • Enhancing our supply chain defenses so that

    deployments on Vercel remain secure by default

    : stricter policies on lifecycle/postinstall scripts, lockfile hygiene, and registry validation.

  • Tightening internal CI/CD controls and developer tooling to catch suspicious package behavior early.

  • For teams using pnpm, consider enabling the new setting introduced in pnpm 10.16 to delay dependency updates (e.g., 24 hours). This helps reduce risk from compromised versions that are discovered and removed shortly after publishing.minimumReleaseAge

  • Audit your dependencies (direct & transitive) to check for packages from these affected namespaces.

  • Rebuild with pinned safe versions and clean lockfiles ().pnpm ci

  • Rotate any npm / GitHub / CI/CD tokens that may have been used in environments where compromised dependencies were present.

  • Inspect GitHub repos for unauthorized workflows or unexpected additions..github/workflows

  • Enforce least privilege (especially in automated workflows), and limit lifecycle script permissions.

  • September 8, 2025

    — Qix / Tinycolor / core package compromise discovered.

  • September 9, 2025

    — DuckDB issue identified.

  • September 15-16, 2025

    — CrowdStrike / Tinycolor “worm” style propagation detected; Vercel detection expanded.

  • September 16, 2025

    — Customer notifications, cache purges, safe rebuilds underway.

Action

Status

Blocklisted known compromised versions from the Tinycolor, CrowdStrike, Qix, and DuckDB-affected packages

✅ Completed

Purged build caches for Vercel projects using those versions

✅ Completed for impacted projects

Coordinated safe rebuilds with clean dependencies / pinned safe versions

✅ In progress / completed for impacted ones

Raised platform alerting & detection thresholds for new package publishes matching the Shai-Halud indicators

✅ Elevated monitoring active

securitysupply-chainnpmvulnerabilityincident

Source: original entry ↗

More from Vercel

Follow Vercel to get its new changes in your feed and email digest.

Feature

OpenAI Decisions API now available on AI Gateway

OpenAI's Decisions API is now accessible through Vercel's AI Gateway with an OpenAI-compatible endpoint, enabling decision models to answer typed questions and return probabilities, choices, and scores for routing, triage, and guardrails use cases. Support is available across the OpenAI SDK, AI SDK, HTTP API, and CLI with the latest versions.

ai-gatewayopenaiapidecisionssdks
Feature

Timestamp attributes now supported in Vercel Flags

Vercel Flags now supports timestamp attributes for entities, allowing you to create time-based targeting rules. Use this feature to run limited-time campaigns, show content between specific dates, or target users based on registration date.

flagstargetingfeaturetimestampscampaigns
Feature

Glyph Cluster now available in stealth on AI Gateway

Glyph Cluster, a reasoning model for coding and long-context analysis, is now available as a stealth model on Vercel's AI Gateway for Pro and Enterprise plan teams with purchased AI Gateway credits at no cost during the stealth period. The model supports function calling, streams responses, and can be accessed via AI SDK, OpenAI-compatible APIs, and coding agents.

ai-gatewaymodelscodingstealth
See all Vercel changes →