← Zapier

2025 Zapier — unauthorized publication access to scoped npm packages (supply-chain hardening wave)

2025 Unknown records affected Share on X

Data compromised

none confirmed; developer package integrity and signing trust as the articulated risk

Technical writeup

In November 2025, Zapier published developer-facing incident notes describing unauthorized access to a subset of its public npm packages and coordinated mitigation (package rotations, CLI hygiene). The vendor stated end-user products continued to operate normally and that it had not seen evidence of data loss, positioning the event primarily as developer-publisher and dependency-integrity exposure rather than a customer-database breach.

Root cause

Compromised or leaked publisher credentials / npm maintainer-plane access (per vendor incident summary)

References