Is Shai-Hulud Back? Compromised Bitwarden CLI Contains a Self-Propagating npm Worm
ID: 58313c80-45e6-50f3-a430-d924bc982cd1
STIX ID: report--58313c80-45e6-50f3-a430-d924bc982cd1
Feed Name: Aikido Security's Blog
A malicious 2026.4.0 release of the npm package `@bitwarden/cli` (published via a compromised CI/CD pipeline) installs a multi-stage credential-stealing worm that harvests SSH keys, cloud secrets (AWS, GCP, Azure), npm/GitHub tokens, and other developer secrets, exfiltrates data to public GitHub repositories and to `audit.checkmarx.cx`, and propagates by publishing/reusing stolen tokens; the report includes payload/preinstall SHA256 hashes, filenames, C2 URLs, and remediation/detection guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
