Vulnerabilities & Exploits · Supply Chain

Free Zapier Account Reaches the Package Supply Chain

Five ordinary weaknesses lined up into platform-level trust. A free Zapier account was enough to reach code that runs in authenticated sessions and to touch packages that ship across Zapier’s own user base, so patching one bug would miss the real break: the chain crosses from user code into the platform’s publishing and session-loading paths.

The key step was memory, not the environment. Zapier deleted AWS credentials from the Lambda environment, but that did not erase the bytes from process memory, so researchers could recover live STS tokens, pull private images, and find a leaked NPM publish token with write access to packages including zapier-platform-core, zapier-platform-cli, and zapier-design-system. Zapier revoked the token, tightened the AWS role in February 2026, and confirmed remediation in March.

2 sources · May 28

Timeline

Sources

Part of the PlainSec briefing for 2026-05-28

Every edition of this story: Free Zapier Account Reaches the Package Supply Chain

More from today