Historical disclosure revision 2
Disclosures and evidence
Revision 2 of 2 · Evidence cutoff Oct 7, 2026, 6:25 PM UTC
9 prior statements preserved · 16 statements added. Attributed source statements retain the source’s qualifications.
What the company disclosed
Zapier stated: “At around 5:50 AM UTC on November 24, 2025, Zapier became aware that a subset of our NPM packages were involved in a supply chain compromise that injected malicious code in their packages.” Status update: 2025-11-24T15:58:41Z (investigating).
Zapier stated: “Overview: At 5:50AM UTC on 11/24/2025, Zapier detected unauthorized modifications to certain npm packages associated with our Developer Platform, resulting from a third-party supply chain compromise known as Shai-Hulud .”
Zapier stated: “Root Cause: Zapier has a second order dependency on an open source library called asyncapi/specs. As per reports from Aikido Security, first infected packages were detected at 3:16AM UTC on 11/24/2024 from AsyncAPI . During routine processing to keep our dependencies up-to-date, the compromised library containing malicious code was downloaded, and pushed unauthorized updates to some of our developer platform npm libraries. We've discovered no evidence, and received no reports of compromise of any developer credentials or session tokens.”
Operational impact
Zapier stated: “At this time, all Zapier products are operating as expected and are not known to be affected.” Status update: 2025-11-24T15:58:41Z (investigating).
Zapier stated: “Zapier Functions is currently offline out of an abundance of caution. For updates about Functions specifically, you can follow along here: https://status.zapier.com/incidents/01KAVFSJ0GVZJ24WW3GJ9BK7G7.” Status update: 2025-11-24T18:02:56.557Z (monitoring).
Zapier stated: “As part of our incident response efforts, Zapier Functions (in Closed Beta) was down for 2 hours and 18 minutes on November 24th (4:14pm UTC to 6:32pm UTC). Impacted customers were notified via email and our status page.”
Reported data impact
Zapier stated: “Verified cloud controls, including IMDSv2, and monitoring showed no credential harvesting or lateral movement since the event.”
Zapier stated: “Zapier Account Owners/Users - Zapier accounts and products were not impacted by this incident, and no action was needed by Zapier account owners/users. We've discovered no evidence, and received no reports of any customer data loss or exposure of data as a result of this incident. During our mitigation efforts, certain services supporting Zaps needed to be restarted, resulting in some Zaps temporarily not completing. Customers with Zaps pending completion were notified via email.”
Response
Zapier stated: “Affected versions have been deprecated, and developers can use the latest versions to ensure they're unaffected.” Status update: 2025-11-24T15:58:41Z (investigating).
Zapier stated: “Our team is currently investigating.” Status update: 2025-11-24T15:58:41Z (investigating).
Zapier stated: “Our Engineering and Security team are continuing to monitor this situation.” Status update: 2025-11-24T18:02:56.557Z (monitoring).
Zapier stated: “Communications and guidance have been sent to Zapier Developers with the following guidance:” Status update: 2025-11-24T19:20:29.046Z (resolved).
Zapier stated: “• For integration developers make sure that you have **_not_** pushed new versions with these packages installed in the timeframe above [5:50AM UTC to 2:03PM UTC].” Status update: 2025-11-24T19:20:29.046Z (resolved).
Zapier stated: “If you pushed a new version with these packages installed, please rotate secrets and private keys with updated values using zapier env or through [developer.zapier.com](http://developer.zapier.com).” Status update: 2025-11-24T19:20:29.046Z (resolved).
Zapier stated: “Deprecated and then fully unpublished all compromised package versions.”
Zapier stated: “Verified mandatory 2FA for users in the affected environment and confirmed the access did not come from a compromised account.”
Zapier stated: “Paused all automatic dependency updates to stop upstream packages from being pulled pending further review.”
Zapier stated: “Blocked pushes using impacted package versions to prevent recurrence.”
Zapier stated: “Rebuilt all CI and build runners and cleared all runner caches, including S3 caches, to remove any contaminated artifacts.”
Zapier stated: “Rotated all potentially exposed credentials and tokens, including runner variables and repository or project secrets.”
Zapier stated: “Tightened CI and build pipeline protections with new detections and preventions for known malware indicators such as specific SHAs, processes, bun environment setup, and pre or post install scripts.”
Zapier stated: “Engaged an independent security vendor to perform additional investigation and confirm findings.”
Zapier stated: “Developers using the Zapier Developer Platform - No integrations were packaged with malware infected Zapier packages, and our incident response team blocked pushes using infected versions as an additional mitigation step.”
Dates and disclosures
Zapier stated: “The affected packages were unpublished at 10:30AM UTC on 11/24/2025, and remaining platform packages were deprecated at 2:30PM UTC. Our developer community was informed of the impacted packages at 3:58PM UTC and provided instructions to mitigate impact in case the packages were in use. This incident did not affect Zapier’s products, infrastructure or customer accounts, other than one product released in Closed Beta that was down due to incident response mitigation efforts and certain Zaps that did not complete during such efforts (see below).”
Qualifications and uncertainty
Zapier stated: “We've discovered no evidence, and received no reports of any impact to the Zapier Developer Community, given that we have no evidence that the infected packages were installed by the Developer Community in the 4 hours and 40 minute window that the packages were available.”
Disclosure sources and provenance
- Zapier Publisher posted November 24, 2025Document form: PUBLIC_DISCLOSUREPublisher HTTPS source · Retrieved Oct 7, 2026, 6:07 PM UTC · Retained Oct 7, 2026, 6:07 PM UTC
- Current captured representation; historical byte snapshots are unknown.
- Zapier Captured Oct 7, 2026, 6:07 PM UTC; publisher posting time is unknownDocument form: PUBLIC_DISCLOSUREPublisher HTTPS source · Retrieved Oct 7, 2026, 6:07 PM UTC · Retained Oct 7, 2026, 6:07 PM UTC
Dates quoted in the source, including signature/report dates, do not establish publisher posting time.
- Current captured representation; historical byte snapshots are unknown.
Evidence limitations
- Attributed publisher/researcher reports establish what was reported, not independent verification of criminal activity or unique affected humans.
- Current captured representations support controlled retrospective disclosure views; actual historical byte snapshots are unknown.