frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Zapier just had a supply chain attack

1•hoppp•30m ago
Zapier had a supply chain attack. They sent out some emails containing the compromised dependencies

At 5:50AM UTC on 11/24/2025, Zapier became aware that a subset of our NPM packages had unauthorized modifications made to them in an apparent supply chain compromise. The unauthorized core platform packages were unpublished by 10:30AM UTC. The rest were deprecated by 2:03PM UTC. List of Zapier NPM packages impacted and versions are below:

zapier-platform-cli 18.0.2

zapier-platform-cli 18.0.3

zapier-platform-cli 18.0.4

zapier-platform-core 18.0.2

zapier-platform-core 18.0.3

zapier-platform-core 18.0.4

zapier-platform-legacy-scripting-runner 4.0.2

zapier-platform-legacy-scripting-runner 4.0.3

zapier-platform-legacy-scripting-runner 4.0.4

zapier-platform-schema 18.0.2

zapier-platform-schema 18.0.3

zapier-platform-schema 18.0.4

@zapier/ai-actions 0.1.18

@zapier/ai-actions 0.1.19

@zapier/ai-actions 0.1.20

@zapier/ai-actions-react 0.1.12

@zapier/ai-actions-react 0.1.13

@zapier/ai-actions-react 0.1.14

@zapier/babel-preset-zapier 6.4.1

@zapier/babel-preset-zapier 6.4.2

@zapier/babel-preset-zapier 6.4.3

@zapier/browserslist-config-zapier 1.0.3

@zapier/browserslist-config-zapier 1.0.4

@zapier/browserslist-config-zapier 1.0.5

@zapier/eslint-plugin-zapier 11.0.3

@zapier/eslint-plugin-zapier 11.0.4

@zapier/eslint-plugin-zapier 11.0.5

@zapier/mcp-integration 3.0.1

@zapier/mcp-integration 3.0.2

@zapier/mcp-integration 3.0.3

@zapier/secret-scrubber 1.1.3

@zapier/secret-scrubber 1.1.4

@zapier/secret-scrubber 1.1.5

@zapier/spectral-api-ruleset 1.9.1

@zapier/spectral-api-ruleset 1.9.2

@zapier/spectral-api-ruleset 1.9.3

@zapier/stubtree 0.1.2

@zapier/stubtree 0.1.3

@zapier/stubtree 0.1.4

@zapier/zapier-sdk 0.15.5

@zapier/zapier-sdk 0.15.6

@zapier/zapier-sdk 0.15.7

redux-router-kit 1.2.2

redux-router-kit 1.2.3

redux-router-kit 1.2.4

zapier-async-storage 1.0.1

zapier-async-storage 1.0.2

zapier-async-storage 1.0.3

zapier-scripts 7.8.3

zapier-scripts 7.8.4

Comments

toomuchtodo•29m ago
Related:

Zapier Security Incident Packages and Zapier Developers - https://news.ycombinator.com/item?id=46038033 - November 2025

Shai-Hulud Returns: Over 300 NPM Packages Infected - https://news.ycombinator.com/item?id=46032539 - November 2025

Accused, shunned and exiled: The women banished to Ghana's 'witch camps'

https://www.aljazeera.com/features/longform/2025/11/23/accused-shunned-exiled-the-women-banished-...
1•binning•1m ago•0 comments

Gmail: Bulk Promotions deletion requires different browser or incognito disabled

https://twitter.com/andrew_michels/status/1992330739615182998
1•throwaway29303•1m ago•0 comments

Testing MCP Servers with MCP Inspector

https://chrisebert.net/testing-mcp-servers-with-mcp-inspector/
1•rmason•1m ago•0 comments

Y'all ever tried AI expand? this thing's wild

1•angelano•2m ago•0 comments

It's time to de-duplicate the desktops

https://www.theregister.com/2025/11/10/deduplicating_the_desktops/
1•rbanffy•3m ago•0 comments

Costs of AI That Are Eating Your Budget (and How to Fix Them)

1•buttersmoothAI•3m ago•0 comments

Atuin’s New Runbook Execution Engine

https://blog.atuin.sh/introducing-the-new-runbook-execution-engine/
1•emschwartz•4m ago•0 comments

The woman scientist and artist who revolutionized the study of mushrooms

https://hyperallergic.com/1029741/mary-banning-woman-scientist-and-artist-who-revolutionized-the-...
1•binning•4m ago•0 comments

Amid GPS and Ride-Hailing, the Allure of London's Black Cab Endures

https://www.nytimes.com/2025/11/24/world/europe/london-black-cab-taxi-driving-test.html
1•axiomdata316•5m ago•0 comments

CoreWeave Earnings Highlight Risks of Surge in AI Borrowing

https://www.barrons.com/articles/coreweave-earnings-ai-debt-e016553d?gaa_at=eafs&gaa_n=AWEtsqfvCF...
1•zerosizedweasle•6m ago•0 comments

Kagi Hub Belgrade: A home base for Kagi members worldwide

https://blog.kagi.com/kagi-hub
2•buster•7m ago•0 comments

AI has a deep understanding of how this code works

https://github.com/ocaml/ocaml/pull/14369
1•theresistor•7m ago•0 comments

Harnessing intricate, self-organized plasma patterns to destroy PFAS

https://phys.org/news/2025-11-harnessing-intricate-plasma-patterns-destroy.html
1•PaulHoule•12m ago•0 comments

Generative AI Image-Guided Editing Benchmarks

http://springus.io/image-editing-benchmarks
1•geooff_•12m ago•0 comments

HTTP Archive: Page Weight

https://httparchive.org/reports/page-weight
2•coloneltcb•13m ago•0 comments

Amazon Leo satellite internet available for businesses – Techzine Global

https://www.techzine.eu/news/infrastructure/136643/amazon-leo-satellite-internet-available-for-bu...
2•janandonly•14m ago•1 comments

Anthropicnews.com

https://anthropicnews.com/
2•rmason•17m ago•1 comments

Amazon Q CLI has become Kiro CLI

https://docs.aws.amazon.com/amazonq/latest/qdeveloper-ug/command-line.html
2•linksbro•17m ago•1 comments

Windows 10 desktop background wasn't computer generated (2024)

https://www.pcgamer.com/gaming-industry/i-was-shocked-to-find-out-the-windows-10-desktop-backgrou...
1•iansteyn•18m ago•2 comments

Browser Choice Alliance

https://browserchoicealliance.org/
2•gpi•19m ago•0 comments

Amazon Is Using Specialized AI Agents for Deep Bug Hunting

https://www.wired.com/story/amazon-autonomous-threat-analysis/
1•kvam•19m ago•0 comments

The First Large-Scale Cyberattack by AI

https://www.wsj.com/opinion/the-first-large-scale-cyberattack-by-ai-4a1e1a30
1•Bostonian•19m ago•1 comments

Isn't WSL2 just a VM?

https://ssg.dev/isnt-wsl2-just-a-vm/
1•sedatk•19m ago•0 comments

Interactive λ-Reduction

https://deltanets.org/
1•jy14898•22m ago•0 comments

Writing comprehensive integration tests for Django applications

https://www.honeybadger.io/blog/django-integration-testing/
1•joshuap•24m ago•1 comments

'Hassle' and 'humiliation': What it's like traveling with a weak passport

https://www.cnbc.com/2025/11/21/hassle-and-humiliation-what-its-like-traveling-with-a-weak-passpo...
1•rustoo•24m ago•0 comments

Show HN: Create Your Own Wolfer

https://memalign.github.io/m/wolfer/create.html
2•memalign•25m ago•0 comments

Show HN: Promptflix – an early marketplace prototype for AI image/video prompts

https://promptflix.com
1•rapgof•26m ago•1 comments

The Performance Inequality Gap, 2026

https://infrequently.org/2025/11/performance-inequality-gap-2026/
2•speckx•27m ago•0 comments

Gemtext: A Markup Language for Gemini

https://geminiprotocol.net/docs/gemtext.gmi
1•dtj1123•28m ago•0 comments