Editorial draft v2 · Evidence reader R2

Historical disclosure scope: November 24, 2025 status updates and a separate root-cause write-up about that incident. The write-up's publication date remains unknown.

Zapier reported malicious code injected into a subset of npm packages associated with its Developer Platform on November 24, 2025. Early status messages said its products were operating as expected and were not known to be affected; later messages and the write-up described precautionary and mitigation-related interruptions. The company's root-cause account attributed the package modifications to a third-party supply-chain compromise. Status history · Root-cause write-up

Detection and the reported dependency chain

The status page said Zapier became aware around 05:50 UTC on November 24, 2025 that malicious code had been injected into affected packages. The write-up described a Shai-Hulud compromise arriving through a second-order dependency on asyncapi/specs. According to Zapier, routine dependency updating downloaded the compromised library, whose code pushed unauthorized updates to Developer Platform libraries. The upstream detection information was attributed in the write-up to Aikido Security. These are Zapier's reported causal findings, not an independent attribution to a named human actor. Status history · Root-cause write-up

Removal and response

Zapier said it deprecated and fully unpublished compromised versions, blocked pushes using affected versions, paused automatic dependency updates, rebuilt CI and build runners, cleared caches, and rotated potentially exposed credentials and tokens. It also reported verified mandatory two-factor authentication, tighter pipeline protections, and an independent security vendor's investigation. The write-up said the access did not come from a compromised account. These reported measures do not by themselves prove that credentials had been harvested. Root-cause write-up

Source statementTime or interval reported, UTCMeaning in that source
Status guidance05:50–14:03Developer guidance window for checking whether new integration versions were pushed with the packages installed
Write-up10:30Affected packages unpublished
Write-up14:30Remaining platform packages deprecated
Write-up15:58Developer community informed and given mitigation guidance
Write-up4 hours 40 minutesStated availability window used in the developer-impact assessment

The sources describe different windows and actions; this draft does not combine them into a newly reconciled timeline. The status guidance told developers who had pushed affected versions to rotate secrets and private keys. The later write-up said Zapier had no evidence of installations by its developer community during the stated availability window and no evidence or reports of impact to that community. The historical precaution and later assessment remain distinct. Status history · Root-cause write-up

Product effects and scoped negative findings

The early statement that products were operating was followed by a precautionary Zapier Functions shutdown. The write-up reported that this closed-beta product was down for 2 hours 18 minutes, from 16:14 to 18:32 UTC on November 24. It also said restarting services during mitigation temporarily prevented some Zaps from completing and that affected customers were notified. Its broader no-impact description expressly carved out those mitigation effects; it should not become a claim of no operational interruption. Status history · Root-cause write-up

Zapier reported no evidence or reports of compromised developer credentials or session tokens, customer-data loss or exposure, and no credential harvesting or lateral movement shown by its monitoring. It said no integrations had been packaged with infected Zapier packages. These are scoped findings based on the company's investigation, rather than proof that misuse was impossible. The selected sources do not establish an affected-person count or final financial loss. Root-cause write-up

Editorial note

The write-up's overview uses November 24, 2025, but its upstream infected-package clause says November 24, 2024. The retained evidence does not resolve the year discrepancy or reconcile the differently scoped timing windows. Root-cause write-up

Sources

Disclosure history

Article draft version 2 · Evidence reader revision 2 · Evidence cutoff Oct 7, 2026, 6:25 PM UTC

The narrative has editorial wording approval. The evaluations below apply to retained extractive disclosure readers, not to the narrative wording.

Disclosure sources and provenance

  • Zapier Publisher posted November 24, 2025Document form: PUBLIC_DISCLOSUREPublisher HTTPS source · Retrieved Oct 7, 2026, 6:07 PM UTC · Retained Oct 7, 2026, 6:07 PM UTC
    • Current captured representation; historical byte snapshots are unknown.
  • Zapier Captured Oct 7, 2026, 6:07 PM UTC; publisher posting time is unknownDocument form: PUBLIC_DISCLOSUREPublisher HTTPS source · Retrieved Oct 7, 2026, 6:07 PM UTC · Retained Oct 7, 2026, 6:07 PM UTC

    Dates quoted in the source, including signature/report dates, do not establish publisher posting time.

    • Current captured representation; historical byte snapshots are unknown.