logo

Bitwarden CLI Compromised in Supply Chain Attack via GitHub Actions

ID: 1bda9d09-2339-5860-8901-38e63dc4c513

STIX ID: report--1bda9d09-2339-5860-8901-38e63dc4c513

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-04-23

Date Updated: 2026-04-23

Author: Guru Baran

...
...

Socket reports that Bitwarden CLI v2026.4.0 on npm was compromised by an injected malicious file (bw1.js) tied to the Checkmarx supply-chain campaign; the payload (C2: audit.checkmarx.cx/v1/telemetry) harvested GitHub, cloud, npm, SSH and local secrets, exfiltrated data via created public repositories, propagated by republishing packages and injecting GitHub Actions, and established persistence (e.g., shell profile modifications and /tmp/tmp.987654321.lock); organisations should remove the package, rotate exposed credentials, audit GitHub workflows and monitor for Bun execution and outbound connections to the C2.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.