Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Bitwarden CLI Breach Highlights Supply Chain Risks

Bitwarden CLI Breach Highlights Supply Chain Risks

Posted on April 23, 2026 By CWS

Bitwarden CLI Breach Unveiled

In a significant security incident, the Bitwarden CLI has been compromised as part of the Checkmarx supply chain campaign, according to recent analyses by JFrog and Socket. The package affected is identified as @bitwarden/[email protected], with malicious code embedded in the ‘bw1.js’ file. This breach follows a pattern wherein a compromised GitHub Action in Bitwarden’s CI/CD pipeline was exploited, mirroring other incidents within the campaign.

Details of the Compromise

JFrog reported that the compromised package was designed to extract GitHub/npm tokens, .ssh keys, environment variables, shell histories, and cloud secrets, transmitting this data to private domains and through GitHub commits. Although this rogue version is no longer available on npm, the attack vector aligns with previously identified methods in the Checkmarx campaign.

Security researcher Adnan Khan noted the attackers used stolen GitHub tokens to inject a malicious workflow into the GitHub Actions pipeline. This workflow was then used to publish the compromised Bitwarden CLI, marking a significant breach in npm’s trusted publishing model.

The Threat Actor and Attack Analysis

TeamPCP is suspected to be behind this latest attack aimed at Checkmarx. Their social media presence has been curtailed, as their account on the platform X was suspended. OX Security’s investigation highlighted a string within the package, “Shai-Hulud: The Third Coming,” suggesting a continuation of the supply chain attack campaign that emerged last year.

Moshe Siman Tov Bustan from OX Security emphasized the gravity of the incident, noting that data exfiltrated to GitHub is often overlooked by security tools, thus increasing the risk of exposure as it can be accessed by anyone searching the platform.

Response and Mitigation Efforts

Bitwarden confirmed the breach but assured that no user data was accessed. The security team quickly contained the threat, revoking unauthorized access, deprecating the malicious npm release, and implementing corrective measures. The affected package was available only briefly on April 22, 2026, and no legitimate Bitwarden CLI codebase or stored vault data was compromised.

Bitwarden has completed a thorough review of its systems, confirming no further impact on other products or environments. A CVE for the Bitwarden CLI version 2026.4.0 is being issued. This incident underscores the need for heightened vigilance in monitoring supply chain security.

This story is ongoing, and updates will follow as more details emerge.

The Hacker News Tags:Bitwarden, Checkmarx, CLI compromise, data exfiltration, GitHub, GitHub actions, JFrog, malicious package, NPM, OX Security, security breach, Shai-Hulud, Socket, supply chain attack, TeamPCP

Post navigation

Previous Post: Fake Trading Platform Spreads Needle Stealer Malware
Next Post: Cloudsmith Secures $72M in Series C Funding Boost

Related Posts

SecAlerts Cuts Through the Noise with a Smarter, Faster Way to Track Vulnerabilities SecAlerts Cuts Through the Noise with a Smarter, Faster Way to Track Vulnerabilities The Hacker News
Russian Hackers Exploit ClickFix CAPTCHAs in Ukraine Russian Hackers Exploit ClickFix CAPTCHAs in Ukraine The Hacker News
Understand Your Real Attack Surface in 45 Days Understand Your Real Attack Surface in 45 Days The Hacker News
Pentera Enhances AI Security with Validation Engines Pentera Enhances AI Security with Validation Engines The Hacker News
10 npm Packages Caught Stealing Developer Credentials on Windows, macOS, and Linux 10 npm Packages Caught Stealing Developer Credentials on Windows, macOS, and Linux The Hacker News
New Pixnapping Android Flaw Lets Rogue Apps Steal 2FA Codes Without Permissions New Pixnapping Android Flaw Lets Rogue Apps Steal 2FA Codes Without Permissions The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Anthropic Debuts AI-Powered Code Security Plugin
  • Iranian Hackers Prepare for Potential Cyber Disruption
  • AI-Coded Applications: Security Challenges Uncovered
  • Kali365 Exploits Microsoft Codes to Breach Accounts
  • Hackers Exploit MFA to Hijack Microsoft 365 Sessions

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Anthropic Debuts AI-Powered Code Security Plugin
  • Iranian Hackers Prepare for Potential Cyber Disruption
  • AI-Coded Applications: Security Challenges Uncovered
  • Kali365 Exploits Microsoft Codes to Breach Accounts
  • Hackers Exploit MFA to Hijack Microsoft 365 Sessions

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark