Bitwarden CLI Compromised in Supply Chain Attack via GitHub Actions
ID: 1bda9d09-2339-5860-8901-38e63dc4c513
STIX ID: report--1bda9d09-2339-5860-8901-38e63dc4c513
Feed Name: cybersecurityNews.com
Socket reports that Bitwarden CLI v2026.4.0 on npm was compromised by an injected malicious file (bw1.js) tied to the Checkmarx supply-chain campaign; the payload (C2: audit.checkmarx.cx/v1/telemetry) harvested GitHub, cloud, npm, SSH and local secrets, exfiltrated data via created public repositories, propagated by republishing packages and injecting GitHub Actions, and established persistence (e.g., shell profile modifications and /tmp/tmp.987654321.lock); organisations should remove the package, rotate exposed credentials, audit GitHub workflows and monitor for Bun execution and outbound connections to the C2.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
