Checkmarx supply chain attack impacts Bitwarden npm distribution path
ID: 16707f9e-febb-514d-a1da-8b23890b867f
STIX ID: report--16707f9e-febb-514d-a1da-8b23890b867f
Feed Name: Security Affairs
*A compromised version of the Bitwarden CLI (@bitwarden/cli 2026.4.0) was briefly distributed on April 22, 2026 via a Checkmarx supply-chain campaign: a malicious preinstall hook executed a cross-platform loader (bw_setup.js) that fetched Bun and ran a 10 MB obfuscated payload (bw1.js) which harvested SSH keys, cloud credentials, tokens, .env/shell history and exfiltrated data to a fake Checkmarx domain or via GitHub commits; attackers also used stolen GitHub/npm credentials to inject workflows and propagate the compromise. Bitwarden removed the malicious release, revoked access, found no evidence of vault or production-data compromise, and is issuing a CVE while researchers published IOCs and analysis.*
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
