OAuth-Token Supply-Chain Compromise Enables Attacker Access to Google Workspace: The Vercel and Composio Breaches — Threadlinqs Intelligence
As of 2026-08-14, OAuth-Token Supply-Chain Compromise Enables Attacker Access to Google Workspace: The Vercel and Composio Breaches is a high-severity supply chain threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 8 indicators of compromise.
Threat ID: TL-2026-2018 · Severity: HIGH · Status: ACTIVE · Category: SUPPLY_CHAIN
Material Security VP Rajan Kapoor documents a shift in Google Workspace attacks from password-based account takeover to OAuth-token-based intrusion, citing the Vercel breach (a Context.ai OAuth token
This threat documents an emerging OAuth-token-centric attack pattern against Google Workspace tenants, evidenced by two disclosed 2026 supply-chain breaches. In the Vercel case, a Context.ai employee endpoint was infected with Lumma Stealer infostealer malware in February 2026 via a trojanized Roblox 'auto-farm' cheat download, exfiltrating Google Workspace, Supabase, Datadog, and Authkit credentials, including access to the shared support@context.ai account. Separately, a Vercel employee had signed up for Context.ai's 'AI Office Suite' using their Vercel enterprise Google account and granted the app 'Allow All' OAuth permissions against Vercel's enterprise Google Workspace. The attacker used the Context.ai foothold to pivot through this over-scoped grant into Vercel's internal Google Workspace, then enumerated and escalated access into internal Vercel systems, reading environment variables (API keys, tokens, database credentials) that had not been flagged as 'sensitive'. A threat actor using the ShinyHunters name claimed responsibility on BreachForums and demanded $2 million for the alleged data, but Google Threat Intelligence Group assessed the claimant as likely an imposter using an established group's name; no confirmed attribution exists. Vercel disclosed the breach April 20-21, 2026, worked with Mandiant, Microsoft, GitHub, npm, and Socket, found no evidence of compromised npm packages, and now defaults deployment environment variables to 'sensitive'.
In the Composio case, disclosed May 21, 2026, an attacker compromised a Composio employee's Gmail OAuth token, gaining inbox access sufficient to intercept magic-link sign-in emails. This let the attacker authenticate into an internal agentic monitoring tool used to watch for connector failures, then abuse that tool's broad permissions to reach an automated remediation system. The attacker registered malicious tool definitions inside Composio's tool-execution sandbox, achieving arbitrary code execution, then pivoted to an auxiliary credential cache and exfiltrated customer secrets to commercial VPN endpoints. Disclosed impact: roughly 5,241 API keys and 5,001 GitHub OAuth tokens (revoked as a precaution), plus roughly 12 Gmail tokens and smaller sets of tokens for Jira, Slack, HubSpot, Linear, Notion, Google Calendar, Vercel, Sentry, Google Drive, and Bitbucket. Composio has not disclosed what data the attacker actually accessed with the stolen tokens, and no threat actor has been publicly attributed.
The common thread Material Security highlights, and the reason this is filed as a distinct threat rather than a restatement of either breach: OAuth grants survive password resets, don't expire on their own, and are hard to observe at the activity layer — making attacker use of a stolen or over-scoped token functionally indistinguishable from an AI agent legitimately using the same grant to read email and Drive content and act on what it finds.
Weaknesses (CWE)
CWE-284, CWE-269, CWE-522
Target sectors: technology, software-development, cloud-hosting, developer-tools, ai-platforms
Target regions: Global
Timeline
- A Context.ai employee endpoint is infected with Lumma Stealer infostealer malware after downloading a trojanized Roblox 'auto-farm' cheat script, exfiltrating Google Workspace, Supabase, Datadog, and Authkit credentials.
- Context.ai identifies and blocks unauthorized AWS access resulting from the earlier credential theft.
- The Context.ai Chrome extension (ID omddlmnhcofjbnbflmjginpjjblphbgk) implicated in the OAuth compromise is removed from the Chrome Web Store.
- Vercel discloses that an attacker used a stolen Context.ai OAuth token, pivoted through a Vercel employee's 'Allow All' OAuth grant, to access internal Vercel systems and non-sensitive environment variables; ShinyHunters claims responsibility on BreachForums, later assessed as a likely imposter.
- SpecterOps and other researchers publish detailed identity-attack-path analyses of the Vercel/Context.ai OAuth pivot.
- Composio discloses a security incident in which an attacker used a compromised employee Gmail OAuth token to intercept magic-link sign-in emails, escalate through an agentic monitoring tool into a tool-execution sandbox, and exfiltrate roughly 5,241 API keys and 5,001 GitHub OAuth tokens.
- Composio's incident disclosure is updated with additional detail on the scope of affected tokens across Jira, Slack, HubSpot, Linear, Notion, Google Calendar, Vercel, Sentry, Google Drive, and Bitbucket integrations.
- Material Security VP Rajan Kapoor publishes analysis via BleepingComputer connecting the Vercel and Composio breaches as evidence of a broader shift to OAuth-token-based Google Workspace intrusions.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 8 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
SUPPLY_CHAIN, HIGH, threat intelligence, cybersecurity, T1199, T1195, T1204.002, T1059, T1176, T1548, T1550.001, T1555.003, T1528, T1087.004