Live
eineurope/
Home/Global/Topic · Bitwarden CLI npm package compromised in supply chain attack
Global4d ago

Bitwarden CLI npm package compromised in supply chain attack

The official Bitwarden CLI npm package was compromised for 90 minutes, distributing malware that harvested credentials and propagated to other packages.

Sources
1 verified
Location
Updated
Friday, 24 April 2026 at 11:33 UTC
No media · text-only dispatch
Synthesis · 1 sources
The official @bitwarden/cli npm package was compromised on April 22, 2026, distributing a malicious version (2026.4.0) for approximately 90 minutes. The malware harvested npm tokens, GitHub credentials, SSH keys, and cloud platform secrets, exfiltrating encrypted data to attacker-controlled GitHub repositories. Bitwarden confirmed the breach was linked to the broader Checkmarx supply chain attack and stated no user vault data was compromised. The malware also featured self-propagation capabilities, using stolen npm credentials to inject malicious code into additional packages, with security researchers identifying infrastructure overlaps with previous TeamPCP campaigns.
e/eineurope · topic · T-05968