Supply Chain Sabotage: Bitwarden CLI Compromised in Global “Checkmarx” Campaign
ID: 5c07a5ea-567f-5290-bb9e-5c04f31ff53a
STIX ID: report--5c07a5ea-567f-5290-bb9e-5c04f31ff53a
Feed Name: securityonline.info
Threat Score
**Supply-chain compromise of Bitwarden CLI:** Researchers report a malicious npm package release (v2026.4.0) containing bw1.js that was likely injected via a compromised GitHub Action; the payload scrapes memory and environment variables to steal tokens, cloud credentials, SSH keys and exfiltrates data to public repositories, requiring immediate package removal, credential rotation, and persistence hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
