In April 2026, Vercel, known as the developer of the Next.js framework, fell victim to a supply chain attack. This event is reported by the research firm Halborn Security Research in its recent analysis.

The incident affected development infrastructure, creating risks for projects dependent on Vercel tools. Currently, all available information regarding the circumstances of the breach comes exclusively from this primary source.

The lack of independent confirmation or additional technical details from other organizations currently prevents reconstructing the full picture of what occurred. The situation requires monitoring for new data from the cybersecurity community.