logo

Bitwarden CLI Hit by Supply Chain Attack Through GitHub Actions

ID: 6c5f3b0c-7364-57a9-9383-689428fcd983

STIX ID: report--6c5f3b0c-7364-57a9-9383-689428fcd983

Feed Name: Cyber Press

Threat Score
80/100

Date Published: 2026-04-24

Date Updated: 2026-04-24

Author: AnuPriya

...
...

Researchers reported a supply-chain attack that injected a credential-stealing payload into the Bitwarden CLI npm package (@bitwarden/cli v2026.4.0) via a compromised GitHub Actions workflow. The malware harvests GitHub tokens, cloud credentials (AWS/Azure/GCP), npm tokens, and SSH keys, persists via shell profile modification, avoids execution on Russian locales, and exfiltrates stolen data by publishing it to public GitHub repositories (with Dune-themed names); IOCs include the malicious package, C2 IP 94.154.172.43, and https://audit.checkmarx.cx/v1/telemetry.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.