How a Roblox Cheat Script Led to a $2M Vercel Hack
A Context.ai employee downloaded a Roblox cheat script on their work laptop, inadvertently installing the Llama Stealer malware, which harvested browser credentials and OAuth tokens. This single infection created a chain reaction that allegedly gave hackers access to Vercel's internal systems, source code, and employee data, which they are now auctioning for $2 million.
Summary
The incident began on February 26 when a Context.ai employee with privileged system access searched for and downloaded a Roblox auto-farm cheat script on their work laptop. Bundled with the script was a piece of malware called Llama Stealer, which silently harvested the employee's saved browser passwords, session cookies, autofill data, Google Workspace credentials, Supabase keys, and admin account credentials for Context.ai.
Llama Stealer is not a simple virus but a sophisticated, commercially operated malware-as-a-service platform, written in C++ and assembly and active on cybercrime forums since 2022. It evades detection by mimicking human behavior (waiting for mouse movement), bypassing Windows APIs through direct kernel system calls, and using trusted platforms like Telegram, Dropbox, and Steam as fallback communication channels. Its distribution network relies on phishing emails, fake Google ads, compromised websites, and deceptive CAPTCHA pages that trick users into running malicious commands. Microsoft documented nearly 400,000 infections in a single 60-day window in early 2025 before executing a global takedown that seized approximately 2,500 domains โ though activity resurged within weeks.
Cybercrime intelligence firm Hudson Rock connected the dots, finding that Context.ai had exactly one recorded Llama Stealer infection โ this employee โ occurring approximately one month before the Vercel breach. The compromised employee's browser data contained the OAuth client ID for a Context.ai-branded Google Workspace application. Because this OAuth app had delegated access to Google Workspace data, when the credentials were stolen, so was the app's access. The same employee was also a core member of the Context.ai-Vercel integration team, and their browser history contained URLs pointing to an internal Vercel project called 'Valinor.'
Vercel's security advisory attributed the breach to 'the compromise of a third-party AI tool's Google Workspace OAuth application.' Hackers โ claiming to be the known extortion group Shiny Hunters, though this is disputed โ are now selling Vercel's alleged source code, database data, npm tokens, GitHub tokens, and multiple employee account credentials on a public forum for $2 million, while simultaneously demanding a private ransom from Vercel to remove the listing. As proof, they released 580 employee records and a screenshot of what appears to be Vercel's internal enterprise dashboard.
The video concludes with security recommendations: auditing Google Workspace OAuth app permissions and revoking unrecognized access, treating every third-party AI tool as a potential backdoor, and rotating API keys, npm tokens, and other secrets on a regular schedule.
Key Insights
- The speaker argues that Llama Stealer is not a crude virus but a professionally operated malware-as-a-service business, written in C++ and assembly, that rents access to affiliates who handle distribution through phishing, fake Google ads, and deceptive CAPTCHA pages that trick users into running malicious terminal commands.
- The speaker explains that Llama Stealer evades most security tools by bypassing the Windows API entirely and communicating directly with the kernel via system calls, while also using trusted platforms like Telegram, Dropbox, and Steam as fallback data exfiltration channels if primary servers go offline.
- Hudson Rock found that Context.ai had exactly one recorded Llama Stealer infection in its entire history โ this single employee, one month before the Vercel breach โ establishing a direct causal link between the Roblox cheat download and the downstream compromise of Vercel.
- The speaker explains that the critical vulnerability was not just stolen credentials but a Context.ai-branded Google Workspace OAuth app that had delegated access to Workspace data; when the employee's credentials were stolen by Llama Stealer, the malware inherited the OAuth app's permissions as well.
- The hacker โ claiming to be Shiny Hunters, though other actors linked to that group denied involvement โ is simultaneously running a public auction of Vercel's alleged source code and demanding a private ransom from Vercel, using the public listing as leverage in a dual-track extortion strategy.
Topics
Transcript
[0:00] One employee, one Roblox cheat script, one download. Two months later, hackers are auctioning Verscell source code on a public forum for $2 million. And as proof, they dropped 580 Verscell employee records, including names, account status, a screenshot of what looks like Versel's internal enterprise dashboard, access to npm tokens, GitHub tokens, etc. And this all happened because one employee at a company or startup called context.ai AI over here downloaded Roblox autofarmm scripts on [0:30] their work laptop. So what happened? How did one download on one machine turn into Verscel's source code getting auctioned off? And who is the person, the hacker doing the selling? So today I'm going to break down the full chain, howโฆ
Full transcript available for MurmurCast members
Sign Up to AccessMore from Sabrina Ramonov ๐
Claude + Canva Just Changed Content Creation Forever!
Sabrina Ramanov demonstrates how to combine Claude AI with Canva's new connector to automate visual content creation, covering posters, Instagram carousels, and infographics. The tutorial walks through setup, template customization, uploading personal media, and automating social media publishing using a third-party app called Blotato. The workflow aims to save marketing teams approximately 15 hours per week.
Get Ahead of 99% of People with This 3 Prompt ChatGPT Chain
A short-form video transcript outlines a three-prompt ChatGPT chain designed to help users identify marketable skills, generate a low-cost business idea, and receive actionable daily guidance. The creator claims the method can help users get ahead of 99% of people. The video ends with a social media engagement call-to-action.
Learn 80% of Claude in 23 Minutes (Beginner Tutorial)
This is a beginner-focused tutorial on Claude AI, promising to cover 80% of its core functionality in 23 minutes. The video targets users who are new to the technology and may feel intimidated. It covers setup, prompting, personalization, projects, and building a personal email assistant.
You're Not Behind on AI in 2026 (5 Habits to Catch Up Fast)
A short video guide outlining five habits to help people catch up on AI usage in 2026. The speaker emphasizes developing reflexes around AI-first thinking, verifying outputs, and integrating AI into existing workflows. The core argument is that most people are barely using AI effectively, making it easy to surpass them.
3 Hidden ChatGPT Codes Most People Don't Know
The video presents three supposed 'hidden codes' for ChatGPT: 'Horoszi' to simulate an Alex Hormozi-style business coach, 'unlearn' to surface outdated misconceptions, and 'Eli 10' to simplify complex concepts. The creator uses these claims to drive engagement by encouraging viewers to follow and comment for more codes.