Zapocalypse Attack Lets Threat Actors Hijack Zapier Accounts
ID: 34fc5428-f620-5d4e-acc1-ea595d148c47
STIX ID: report--34fc5428-f620-5d4e-acc1-ea595d148c47
Feed Name: GBHackers
The 'Zapocalypse' research shows a realistic attack chain against Zapier: memory scraping of a Lambda process recovered STS credentials after environment vars were scrubbed, those credentials allowed listing and downloading private ECR images, image build metadata revealed a reusable NPM publish token, and publishing a malicious version of a frontend design-system package would let attacker-controlled JavaScript run in every authenticated user's browser enabling full account takeover actions within Zapier.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
