Editorial draft v2 · Evidence reader R2
Historical disclosure scope: November 24, 2025 status updates and a separate root-cause write-up about that incident. The write-up's publication date remains unknown.
Zapier reported malicious code injected into a subset of npm packages associated with its Developer Platform on November 24, 2025. Early status messages said its products were operating as expected and were not known to be affected; later messages and the write-up described precautionary and mitigation-related interruptions. The company's root-cause account attributed the package modifications to a third-party supply-chain compromise. Status history · Root-cause write-up
Detection and the reported dependency chain
The status page said Zapier became aware around 05:50 UTC on November 24, 2025 that malicious code had been injected into affected packages. The write-up described a Shai-Hulud compromise arriving through a second-order dependency on asyncapi/specs. According to Zapier, routine dependency updating downloaded the compromised library, whose code pushed unauthorized updates to Developer Platform libraries. The upstream detection information was attributed in the write-up to Aikido Security. These are Zapier's reported causal findings, not an independent attribution to a named human actor. Status history · Root-cause write-up
Removal and response
Zapier said it deprecated and fully unpublished compromised versions, blocked pushes using affected versions, paused automatic dependency updates, rebuilt CI and build runners, cleared caches, and rotated potentially exposed credentials and tokens. It also reported verified mandatory two-factor authentication, tighter pipeline protections, and an independent security vendor's investigation. The write-up said the access did not come from a compromised account. These reported measures do not by themselves prove that credentials had been harvested. Root-cause write-up
| Source statement | Time or interval reported, UTC | Meaning in that source |
|---|---|---|
| Status guidance | 05:50–14:03 | Developer guidance window for checking whether new integration versions were pushed with the packages installed |
| Write-up | 10:30 | Affected packages unpublished |
| Write-up | 14:30 | Remaining platform packages deprecated |
| Write-up | 15:58 | Developer community informed and given mitigation guidance |
| Write-up | 4 hours 40 minutes | Stated availability window used in the developer-impact assessment |
The sources describe different windows and actions; this draft does not combine them into a newly reconciled timeline. The status guidance told developers who had pushed affected versions to rotate secrets and private keys. The later write-up said Zapier had no evidence of installations by its developer community during the stated availability window and no evidence or reports of impact to that community. The historical precaution and later assessment remain distinct. Status history · Root-cause write-up
Product effects and scoped negative findings
The early statement that products were operating was followed by a precautionary Zapier Functions shutdown. The write-up reported that this closed-beta product was down for 2 hours 18 minutes, from 16:14 to 18:32 UTC on November 24. It also said restarting services during mitigation temporarily prevented some Zaps from completing and that affected customers were notified. Its broader no-impact description expressly carved out those mitigation effects; it should not become a claim of no operational interruption. Status history · Root-cause write-up
Zapier reported no evidence or reports of compromised developer credentials or session tokens, customer-data loss or exposure, and no credential harvesting or lateral movement shown by its monitoring. It said no integrations had been packaged with infected Zapier packages. These are scoped findings based on the company's investigation, rather than proof that misuse was impossible. The selected sources do not establish an affected-person count or final financial loss. Root-cause write-up
Editorial note
The write-up's overview uses November 24, 2025, but its upstream infected-package clause says November 24, 2024. The retained evidence does not resolve the year discrepancy or reconcile the differently scoped timing windows. Root-cause write-up
Sources
Status history — November 24, 2025 updates.
Root-cause write-up — publication date unknown; describes the November 24, 2025 incident.