Vapi identified and contained a supply chain incident on June 3, 2026 involving the Miasma/Shai-Hulud worm that compromised their GitHub repositories. The company removed four malicious npm package versions within a 3-hour window and confirmed that no customer data, customer credentials, Vapi secrets, or keys beyond the initial compromised access token were accessed or exfiltrated. No customer action is required as the malicious packages had zero downloads before removal.