Zapier — Cyber Attacks, Breaches & Threat Activity

Threat entity extracted from intelligence sources

Frequency
21
occurrences
First Seen
November 24, 2025
Last Seen
May 29, 2026

Zapier is a organization tracked across 7 threat clusters and 21 intelligence report mentions on ThreatCluster. First observed November 24, 2025; most recent activity May 29, 2026.

Overview

Zapier is a widely used SaaS workflow automation platform that connects apps and automates tasks. The provided articles do not mention Zapier directly; however, they describe a major supply-chain intrusion (Shai-Hulud) targeting npm packages and GitHub repositories, highlighting how automation platforms and their customers can be affected by compromised dependencies, malicious packages, or repository breaches.

Related Threat Clusters

  • Threat Actors Exploit n8n Webhooks for Malware Delivery and Phishing

    Cybercriminals are exploiting the n8n AI workflow automation platform to conduct phishing campaigns and deliver malware. Between October 2025 and March 2026, there was a 686% increase in phishing emails utilizing…

    9 articles · Updated April 16, 2026
  • Shai Hulud npm Worm Compromises Over 26,000 Repositories

    The Shai Hulud worm has compromised more than 26,000 public repositories in a supply chain attack. The attack targeted various npm packages, exploiting vulnerabilities that allowed unauthorized access to these…

    32 articles · Updated November 24, 2025
  • Zapier Exploit Chain Grants Unauthorized NPM Access

    Researchers at Token Security disclosed a five-stage exploit chain that allowed a free Zapier account to gain write access to both public and internal NPM packages. Each stage of the chain exploited known anti-patterns,…

    8 articles · Updated May 28, 2026
  • Shai-Hulud Malware Compromises 25K GitHub Repositories via npm Packages

    The Shai-Hulud malware has re-emerged, infecting over 500 trojanized npm packages and compromising secrets from more than 25,000 developers within three days. The malicious packages, including those from popular…

    4 articles · Updated November 24, 2025
  • Shai-Hulud Malware Infects npm Packages, Compromising Thousands of Repositories

    A new wave of the Shai-Hulud malware has compromised nearly 500 npm packages, affecting over 26,000 GitHub repositories. This self-replicating worm, which targets developers' credentials and secrets, has been linked to…

    43 articles · Updated November 29, 2025
  • Zapier’s NPM Account Hacked, Packages Infected with Malware

    Zapier's NPM account was compromised, leading to multiple packages being infected with malware. The incident has raised alarms about the security of third-party packages in the Node.js ecosystem. Users of the affected…

    2 articles · Updated November 24, 2025
  • Zapier’s NPM Account Hacked, Packages Infected with Malware

    Zapier's NPM account was hacked, leading to multiple packages being infected with malware. The incident has raised concerns about the security of third-party packages in the NPM ecosystem, affecting users who rely on…

    2 articles · Updated November 24, 2025

Recent Intelligence Reports

  • With Complex Cloud Integrations, Small Errors Lead to Major Compromises — Darkreading · May 29, 2026
  • Zapier exploit chain shows how known anti — Feeds2.Feedburner · May 28, 2026
  • Hackers Exploit n8n Webhooks to Spread Malware — Gbhackers · April 16, 2026
  • Hackers Exploit n8n Webhooks to Spread Malware — Gbhackers · April 16, 2026
  • The n8n n8mare: How threat actors are misusing AI workflow automation — Blog.Talosintelligence · April 15, 2026
  • PostHog admits Shai-Hulud 2.0 was its biggest ever security bungle — Theregister · November 29, 2025
  • PostHog admits Shai — Theregister · November 28, 2025
  • Shai Hulud malware attack compromises 19,000 GitHub repositories — Securitybrief · November 28, 2025

CVSS v3.1 Breakdown