Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Zapier

Zapier Vendor Cyber Rating & Cyber Score

zapier.com

Chase the spark at ZapConnect 2025. Register + refer to win prizes → zapier.com/zapconnect


Zapier A.I CyberSecurity Scoring

Zapier
Company Information
Website:https://zapier.com/?utm_source=linkedin
Employees number:1,409
Number of followers:344,475
NAICS:5112
Industry Type:Software Development
Homepage:zapier.com
Zapier Risk Score (AI oriented)
Between 700 and 749
logo
ZapierSoftware Development
Updated:
29/03/2026
724/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Zapier Global Score (TPRM)
xxxx
logo
ZapierSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Zapier
ZapierModerate
Current Score
724Ba (MODERATE)
01000
2 incidents
-24 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
728Before Incident
MAY 2026
726Before Incident
APRIL 2026
725Before Incident
MARCH 2026
747Before Incident
FEBRUARY 2026
747Before Incident
JANUARY 2026
747Before Incident
DECEMBER 2025
745Before Incident
Cyber Attack
01 Dec 2025Zapier
npm, Inc.: Shai-Hulud 2.0 NPM malware attack exposed up to 400,000 dev secrets

Shai-Hulud 2.0 NPM and GitHub Secrets Exposure

719After Incident
CRITICAL-26
NPM1764705355
The second Shai-Hulud attack last week exposed around 400,000 raw secrets after infecting hundreds of packages in the NPM (Node Package Manager) registry and publishing stolen data in 30,000 GitHub repositories. Although just about 10,000 of the exposed secrets were verified as valid by the open-source TruffleHog scanning tool, researchers at cloud security platform Wiz say that more than 60% of the leaked NPM tokens were still valid as of December 1st. The Shai-Hulud threat emerged in mid-September, compromising 187 NPM packages with a self-propagating payload that identified account tokens using TruffleHog, injected a malicious script into the packages, and automatically published them on the platform. In the second attack, the malware impacted over 800 packages (counting all infected versions of a package) and included a destructive mechanism that wiped the victim’s home directory if certain conditions were met. Pace of new GitHub accounts publishing secrets on new repositories Source: Wiz Wiz researchers analyzing the leak of secrets that the Shai-Hulud 2.0 attack spread over 30,000 GitHub repositories, found that the following types of secrets have been exposed: about 70% of the repositories had a contents.json file with GitHub usernames and tokens, and file snapshots half of them had the truffleSecrets.json file containing TruffleHog scan results 80% of the repositories had the environment.json file with OS info, CI/CD metadata, npm package metadata, and GitHub
INCIDENT DETAILS -
TYPE
Supply Chain Attack
IMPACT
Data Compromised: 400,000 raw secrets exposedSystems Affected: NPM registry, GitHub repositoriesOperational Impact: Potential data exfiltration and system wipesIdentity Theft Risk: High (exposure of GitHub tokens and PII)
DATA BREACH
GitHub usernames and tokensTruffleHog scan resultsOS infoCI/CD metadatanpm package metadataNumber Of Records Exposed: 400,000 raw secretsSensitivity Of Data: High (60% of leaked NPM tokens still valid as of December 1st)Data Exfiltration: Yes (published in GitHub repositories)contents.jsontruffleSecrets.jsonenvironment.jsonPersonally Identifiable Information: GitHub usernames and tokens
NOVEMBER 2025
767Before Incident
Cyber Attack
24 Nov 2025Zapier
Zapier

Supply Chain Attack on Zapier’s NPM Account with Shai Hulud Malware

745After Incident
CRITICAL-22
ZAP0911609112525
A sophisticated supply chain attack compromised Zapier’s NPM account, infecting 425 packages with the Shai Hulud malware, a self-propagating worm targeting the Bun runtime environment. The attack weaponized widely used libraries (e.g., `@zapier/mcp-integration`), which collectively receive ~132 million monthly downloads, exposing thousands of downstream applications and organizations.The malware harvested credentials and exfiltrated them to GitHub repositories (26,300+ exposed repos), enabling lateral movement, unauthorized cloud access, and further compromises. While some payloads failed to deploy fully (missing `bun_environment.js`), the staging code (`setup_bun.js`) established persistence, leaving systems vulnerable to remote updates.The incident forced organizations to audit dependencies, rotate credentials, and monitor for IOCs, highlighting critical gaps in supply chain security and dependency integrity within the npm ecosystem. The scale of credential leaks and potential downstream breaches amplifies the long-term operational and reputational risks.
INCIDENT DETAILS -
TYPE
supply chain attackmalware infectioncredential harvesting
MOTIVATION
credential theftlateral movementunauthorized cloud accesssupply chain disruption
IMPACT
credentialssecretsWindowsLinuxmacOScompromised development pipelinesproduction environment riskslateral movement potentialhigh (due to widespread package usage)trust erosion in NPM ecosystemIdentity Theft Risk: high (26,300 exposed repositories with leaked credentials)
DATA BREACH
credentialssecretsenvironment variablesNumber Of Records Exposed: 26,300 (GitHub repositories)Sensitivity Of Data: high (authentication secrets, API keys, tokens)Data Exfiltration: yes (to GitHub repositories)JavaScript (setup_bun.js)runtime scripts (bun_environment.js)
OCTOBER 2025
767Before Incident
SEPTEMBER 2025
767Before Incident
AUGUST 2025
767Before Incident
JULY 2025
767Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Zapier ?
?
What was Zapier's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Zapier's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Zapier's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Zapier's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Zapier's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Zapier's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Zapier's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Zapier's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Zapier's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Zapier's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Zapier's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Zapier's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Zapier ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Zapier's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?