Vulnerabilities · 139 days ago
A trusted package release can now steal the secrets of the systems that install it. In this case, the compromise was not just tampering with code. It turned a normal CLI update into a way to pull GitHub tokens, npm credentials, SSH keys, .env files, shell history, and cloud secrets from downstream environments and CI runs.
Socket says @bitwarden/cli@2026.4.0 was published with malicious code in bw1.js after attackers abused a compromised GitHub Action in Bitwarden’s CI/CD pipeline. The rogue version is no longer on npm, but the impact is broader than the package itself because the same workflow path can expose secrets already present in build jobs and developer machines.
The non-obvious risk is persistence. Once CI secrets or developer credentials are exposed, patching the package does not undo the theft, and the stolen tokens can be used to push more malicious workflow changes or package updates.
7 sources covering this story
Malicious npm Dependency Linked to AI Assisted Commit Targets Crypto W
Researchers uncover a malicious npm dependency linked to an AI‑assisted code commit that steals sensitive data and exposes crypto wallets
Why a recent supply-chain attack singled out security firms Checkmarx and Bitwarden
Security firms find themselves especially exposed.
Ongoing supply-chain attack targets security, dev tools
: Vendor confirms repo data exposure after Lapsus$ claims source code, secrets dump
Bitwarden NPM Package Hit in Supply Chain Attack
Tied to a fresh Checkmarx supply chain attack claimed by TeamPCP, the incident references the Shai-Hulud worm.
Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign
Bitwarden CLI 2026.4.0 was compromised via GitHub Actions in Checkmarx campaign, exposing secrets and distributing malicious npm code
Bitwarden CLI npm package compromised to steal developer credentials
The Bitwarden CLI was briefly compromised after attackers uploaded a malicious @bitwarden/cli package to npm containing a credential-stealing payload capable of spreading to other projects.
Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain ...
Bitwarden CLI 2026.4.0 was compromised in the Checkmarx supply chain campaign after attackers abused a GitHub Action in Bitwarden’s CI/CD pipeline.
Part of the PlainSec briefing for 2026-04-30