Vercel and GitHub confirm npm supply chain security; packages have not been tampered with
Vercel’s official account announced on April 21, 2026 that, after a joint verification with GitHub, Microsoft, npm, and Socket, it confirmed that all packages Vercel published on npm had not been tampered with and that the supply chain remains secure. A security advisory updated the same day stated that, in this incident, the data that was leaked was customer environment variables that were not marked as “sensitive”; after being decrypted in the backend, they were stored in plaintext form.
MarketWhisper·4m ago












