INTEL_REPORT
Trend Micro Research · published 4/20/2026, 12:00:00 AM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
The Vercel Breach: OAuth Supply Chain Attack Exposes the Hidden Risk in Platform Environment Variables An OAuth supply chain compromise at Vercel exposed how trusted third party apps and platform environment variables can bypass traditional defenses and amplify blast radius. This article examines the attack chain, underlying design tradeoffs, and what it reveals about modern PaaS and software supply chain risk. The Vercel Breach: OAuth Supply Chain Attack Exposes the Hidden…
https://www.trendmicro.com/en_us/research/26/d/vercel-breach-oauth-supply-chain.html
sha256:354891333a4edcece5b97ecaf5e2898ac658694b9223a09d4ab8be1b3040a7e1
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| s3.amazonaws.com |
| Open → |
| domain | useridentity.accesskeyid | Open → |
| domain | protopayload.authenticationinfo.principalemail | Open → |
| domain | protopayload.requestmetadata.callerip | Open → |
| domain | protopayload.methodname | Open → |
| domain | compute.instances.list | Open → |
| domain | iam.serviceaccountkeys.create | Open → |
| domain | microsoft.compute | Open → |
| domain | microsoft.authorization | Open → |
| domain | 110671459871-30f1spbu0hptbs60cb4vsmv79i7bbvqj.apps.googleusercontent.com | Open → |
| domain | env.read | Open → |
| domain | env.list | Open → |
| cve | CVE-2026-33634 | Open → |