Vercel OAuth Chain Gains State Attribution: Lazarus, Storm-2372, UNC5537 Join Scattered Spider; CALENDAR + Trivy KEV in Scope
Since last coverage, the Vercel OAuth breach has escalated significantly: Lazarus Group, Storm-2372, and UNC5537 are now attributed alongside the previously reported Scattered Spider, with seven ATT&CK techniques mapped — all centered on credential and OAuth token abuse (T1078.004, T1550.001, T1552.001) and internal data collection (T1213). Storm-2372's known specialization in OAuth device code flow attacks maps precisely to the T1550.001 application access token technique documented here, making that cluster the most technically coherent participant. CVE-2026-33634 in Aquasecurity's Trivy scanner (EPSS 0.21, KEV-listed, past-due April 9 remediation window) is now associated with the operation — relevant because a vulnerability in a security scanning tool embedded in CI/CD pipelines creates a plausible vector for credential exfiltration from within trusted build infrastructure. CALENDAR malware attribution (a known DPRK implant family) and confirmed data breach status represent material escalations from the initial disclosure.
The four-actor attribution (Scattered Spider, Lazarus, Storm-2372, UNC5537) warrants scrutiny — Trend Micro's analysis of a complex incident routinely cites multiple actors as precedent or comparison, and not all will have been direct participants. Storm-2372 and Scattered Spider are the most coherent attributions given the OAuth attack chain; Lazarus's CALENDAR implant, if confirmed on Vercel infrastructure, suggests either independent DPRK access or downstream exploitation of credentials exfiltrated by the initial actor. What matters for financial services exposure is that Vercel is the steward of Next.js and a significant slice of JavaScript OSS ecosystem infrastructure — environment variable exfiltration from that position has potential blast radius well beyond Vercel's own internal systems if the threatened supply chain pivot materializes. The sibling stories (6585, 6586) cover the Scattered Spider initial access angle.
Four named actors on a single incident is attribution past the point of coherence — the most technically defensible reading is that Storm-2372's OAuth device-code specialty drove initial entry (T1550.001 maps cleanly), Scattered Spider owned the social-engineering front, and the Lazarus CALENDAR artefact reflects downstream exploitation of exfiltrated credentials rather than joint operation. The real story is unchanged from the morning and getting worse: DPRK implants showing up inside the Next.js steward's blast radius while the attacker publicly threatens cascading supply-chain moves into Vercel-owned JS libraries. CVE-2026-33634 in Trivy landing in this cluster is the confirmation that scanner-in-CI is a live credential-exfil surface, not a theoretical one.