logo

Zapocalypse Attack Lets Threat Actors Hijack Zapier Accounts

ID: 34fc5428-f620-5d4e-acc1-ea595d148c47

STIX ID: report--34fc5428-f620-5d4e-acc1-ea595d148c47

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-05-29

Date Updated: 2026-05-29

Author: Divya

...
...

The 'Zapocalypse' research shows a realistic attack chain against Zapier: memory scraping of a Lambda process recovered STS credentials after environment vars were scrubbed, those credentials allowed listing and downloading private ECR images, image build metadata revealed a reusable NPM publish token, and publishing a malicious version of a frontend design-system package would let attacker-controlled JavaScript run in every authenticated user's browser enabling full account takeover actions within Zapier.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.