Bitwarden CLI Hacked: Ongoing Supply Chain Attack Exposed

Date:

New Malware Attack Targets Bitwarden CLI in Supply Chain Breach

On April 22, 2026, Bitwarden CLI fell victim to a significant malware attack linked to the ongoing Checkmarx campaign. The malicious version of the package, identified as @bitwarden/cli@2026.4.0, contained harmful code that could steal sensitive data such as GitHub tokens and cloud secrets.

While no end-user data was compromised, the breach potentially affected developers who downloaded the tainted package during a brief window. Security analyses revealed that the attack exploited a compromised GitHub Action in Bitwarden’s development pipeline, raising concerns about supply chain vulnerabilities.

Bitwarden has since revoked access and deprecated the malicious package. To protect yourself, avoid downloading packages from unverified sources and ensure your security settings are up to date.

Risk Level: Medium – While immediate user data is safe, the incident highlights ongoing threats in software supply chains.

Source: View Original Report

Share post:

spot_imgspot_img

Popular

More like this
Related

Critical PHP Object Injection Vulnerability Found in GiveWP Plugin

A recently discovered vulnerability in the GiveWP plugin poses...

AI Advances Strengthen Cybersecurity: Wordfence Unveils Critical Vulnerability Discovery

Wordfence has revealed significant advancements in its incorporation of...

Critical Unauthenticated Account Takeover Vulnerability Found in TranslatePress Plugin

On August 11, 2026, a significant security vulnerability was...

Hackers Target WordPress Sites in miniOrange Authentication Bypass Attacks

In recent weeks, hackers have escalated their attacks on...