logo

Checkmarx supply chain attack impacts Bitwarden npm distribution path

ID: 16707f9e-febb-514d-a1da-8b23890b867f

STIX ID: report--16707f9e-febb-514d-a1da-8b23890b867f

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-04-24

Date Updated: 2026-04-24

Author: Pierluigi Paganini

...
...

*A compromised version of the Bitwarden CLI (@bitwarden/cli 2026.4.0) was briefly distributed on April 22, 2026 via a Checkmarx supply-chain campaign: a malicious preinstall hook executed a cross-platform loader (bw_setup.js) that fetched Bun and ran a 10 MB obfuscated payload (bw1.js) which harvested SSH keys, cloud credentials, tokens, .env/shell history and exfiltrated data to a fake Checkmarx domain or via GitHub commits; attackers also used stolen GitHub/npm credentials to inject workflows and propagate the compromise. Bitwarden removed the malicious release, revoked access, found no evidence of vault or production-data compromise, and is issuing a CVE while researchers published IOCs and analysis.*

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.