New Malware Attack Targets Bitwarden CLI in Supply Chain Breach
On April 22, 2026, Bitwarden CLI fell victim to a significant malware attack linked to the ongoing Checkmarx campaign. The malicious version of the package, identified as @bitwarden/cli@2026.4.0, contained harmful code that could steal sensitive data such as GitHub tokens and cloud secrets.
While no end-user data was compromised, the breach potentially affected developers who downloaded the tainted package during a brief window. Security analyses revealed that the attack exploited a compromised GitHub Action in Bitwarden’s development pipeline, raising concerns about supply chain vulnerabilities.
Bitwarden has since revoked access and deprecated the malicious package. To protect yourself, avoid downloading packages from unverified sources and ensure your security settings are up to date.
Risk Level: Medium – While immediate user data is safe, the incident highlights ongoing threats in software supply chains.
Source: View Original Report
