2025 Zapier — unauthorized publication access to scoped npm packages (supply-chain hardening wave)
Data compromised
none confirmed; developer package integrity and signing trust as the articulated risk
Technical writeup
In November 2025, Zapier published developer-facing incident notes describing unauthorized access to a subset of its public npm packages and coordinated mitigation (package rotations, CLI hygiene). The vendor stated end-user products continued to operate normally and that it had not seen evidence of data loss, positioning the event primarily as developer-publisher and dependency-integrity exposure rather than a customer-database breach.
Root cause
Compromised or leaked publisher credentials / npm maintainer-plane access (per vendor incident summary)