Open Source · · 1 day

Zapier npm packages hit by Shai-Hulud

The Sha1-Hulud "Second Coming" npm worm compromised Zapier packages across the @zapier scope and unscoped zapier-platform packages.

Part of Sha1-Hulud worm spread across npm packages campaign

Zapier disclosed unauthorized modifications to a subset of its npm packages on November 24, 2025. The affected packages were developer tooling for Zapier platform integrations, not the Zapier product runtime, and Zapier said it had no indication of customer data loss.

The compromise lined up with the Sha1-Hulud "Second Coming" wave. Malicious npm releases installed a Bun-based payload that harvested secrets, wrote stolen data into attacker-created GitHub repositories, and tried to spread by abusing npm tokens and GitHub trusted-publishing paths.

Zapier unpublished the core platform packages by 10:30 UTC and deprecated the rest by 14:03 UTC. Its guidance was direct: do not install the affected versions, clean npm caches and local node_modules, reinstall current packages, and rotate secrets if compromised packages were used to publish integrations.

This record keeps Zapier as its own attack because the package scope is specific and officially enumerated. The broader worm remains modeled as the parent campaign.

Appendix · Affected releases

Indicators

  • file_sha256bun_environment.js 62ee164b9b306250c1172583f138c9614139264f889fa99614903c12755468d0
  • file_sha256bun_environment.js f099c5d9ec417d4445a0328ac0ada9cde79fc37410914103ae9c609cbc0ee068
  • file_sha256bun_environment.js cbb9bc5a8496243e02f3cc080efbe3e4a1430ba0671f2e43a202bf45b05479cd
  • file_sha256setup_bun.js a3894003ad1d293ba96d77881ccd2071446dc3f65f434669b49b3da92421901a

References

  1. "Shai-Hulud" Worm Compromises npm Ecosystem in Supply Chain Attack - Unit 42unit42.paloaltonetworks.com
  2. Unauthorized Access to Zapier NPM Packagesdocs.zapier.com
  3. Zapier's NPM Account Compromised in Supply Chain Attackcybersecuritynews.com
  4. Sha1-Hulud the Second Comingstepsecurity.io
  5. Sha1-Hulud the Second Coming Affected Package Liststepsecurity-public-media.s3.us-west-2.amazonaws.com

Source record: oss/attacks/zapier-npm/meta.yaml