Bitwarden CLI Hacked: Ongoing Supply Chain Attack Exposed

Date:

New Malware Attack Targets Bitwarden CLI in Supply Chain Breach

On April 22, 2026, Bitwarden CLI fell victim to a significant malware attack linked to the ongoing Checkmarx campaign. The malicious version of the package, identified as @bitwarden/cli@2026.4.0, contained harmful code that could steal sensitive data such as GitHub tokens and cloud secrets.

While no end-user data was compromised, the breach potentially affected developers who downloaded the tainted package during a brief window. Security analyses revealed that the attack exploited a compromised GitHub Action in Bitwarden’s development pipeline, raising concerns about supply chain vulnerabilities.

Bitwarden has since revoked access and deprecated the malicious package. To protect yourself, avoid downloading packages from unverified sources and ensure your security settings are up to date.

Risk Level: Medium – While immediate user data is safe, the incident highlights ongoing threats in software supply chains.

Source: View Original Report

Share post:

spot_imgspot_img

Popular

More like this
Related

WPScan 4.0.0: Critical XSS Vulnerability Exposed!

WordPress Vulnerability Report: WPScan 4.0.0 Released Introduction The latest version of...

119 Edge Extensions: Malware Disguised as Useful Tools

Cybersecurity Alert: Malware Infiltrates Popular Browser Extensions A recent malware...

200K WordPress Sites Face XSS Risk from Burst Statistics Plugin

Critical Vulnerability Discovered in Burst Statistics Plugin for WordPress On...

Foxconn Cyberattack: Nitrogen Ransomware Strikes WordPress Sites

Cyberattack Hits Foxconn: Major Data Breach Reported Foxconn, the largest...