logo

Is Shai-Hulud Back? Compromised Bitwarden CLI Contains a Self-Propagating npm Worm

ID: 58313c80-45e6-50f3-a430-d924bc982cd1

STIX ID: report--58313c80-45e6-50f3-a430-d924bc982cd1

Feed Name: Aikido Security's Blog

Threat Score
90/100

Date Published: 2026-04-23

Date Updated: 2026-07-24

...
...

A malicious 2026.4.0 release of the npm package `@bitwarden/cli` (published via a compromised CI/CD pipeline) installs a multi-stage credential-stealing worm that harvests SSH keys, cloud secrets (AWS, GCP, Azure), npm/GitHub tokens, and other developer secrets, exfiltrates data to public GitHub repositories and to `audit.checkmarx.cx`, and propagates by publishing/reusing stolen tokens; the report includes payload/preinstall SHA256 hashes, filenames, C2 URLs, and remediation/detection guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.