Wednesday, August 27, 2025

Start of archive·May 16

Top story

The ReadVercel Blog

s1ngularity: supply chain attack in Nx packages

A sophisticated supply chain attack exploited stolen npm credentials to inject malicious code that used LLMs to exfiltrate developer secrets. This signals a new class of AI-enabled threats targeting the infrastructure developers rely on—and exposes how AI tooling (Claude, Gemini, Q CLIs) can become attack surface in build pipelines.

Attack vector: Malicious Nx packages with postinstall scripts using LLMs to scan filesystems for secrets

The briefs

Cross-lab safety collaboration between two AI leaders sets a governance precedent and reveals real-world model vulnerabilities—critical for boards weighing AI deployment risk and regulatory compliance.

First joint safety evaluation between OpenAI and Anthropic

Vercel's new @vercel/slack-bolt adapter removes a critical technical barrier to building production Slack agents, enabling developers to deploy AI-powered workflows that were previously infeasible on serverless platforms.

Official adapter: @vercel/slack-bolt for Slack Bolt.js on Vercel AI Cloud

OpenAI is systematizing AI alignment through public input, signaling a shift toward democratizing AI governance decisions and embedding diverse human values into model defaults—a strategic move that positions the company as addressing safety and legitimacy concerns while setting industry precedent for 'collective alignment' practices.

Survey of 1,000+ people worldwide