Cyberscoop Zapier Exploit Chain Grants Unauthorized NPM Access
Article Content
- •A five-stage exploit chain allowed unauthorized access to Zapier's NPM packages.
- •The vulnerability was based on known anti-patterns and involved a sandbox escape.
- •Zapier responded quickly, revoking a leaked NPM token and tightening security measures.
Researchers at Token Security disclosed a five-stage exploit chain that allowed a free Zapier account to gain write access to both public and internal NPM packages. Each stage of the chain exploited known anti-patterns, culminating in a significant security vulnerability. The attack vector involved a sandbox escape within Zapier's Code by Zapier feature, which executes user-supplied Python and JavaScript in AWS Lambda containers. The vulnerability was reported on February 12, 2026, and was triaged by Zapier within four days, leading to the revocation of a leaked NPM token and tightening of AWS roles. The incident highlights the risks associated with supply chain vulnerabilities in widely used developer tools. No specific CVEs were disclosed in the articles. The current status indicates that the vulnerability has been addressed by Zapier.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (8)
Following this threat?
Track Unc6395, Blaster worm and Token Security in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
BlueMoon Exploit Kit Targeting Chrome and Windows by Multiple State Actors A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of BlueMoon was on August 28, 2026, by the China-aligned threat actor TA412, with subsequent adoption by…