logo

Supply Chain Sabotage: Bitwarden CLI Compromised in Global “Checkmarx” Campaign

ID: 5c07a5ea-567f-5290-bb9e-5c04f31ff53a

STIX ID: report--5c07a5ea-567f-5290-bb9e-5c04f31ff53a

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-04-24

Date Updated: 2026-04-24

Author: Ddos

...
...

**Supply-chain compromise of Bitwarden CLI:** Researchers report a malicious npm package release (v2026.4.0) containing bw1.js that was likely injected via a compromised GitHub Action; the payload scrapes memory and environment variables to steal tokens, cloud credentials, SSH keys and exfiltrates data to public repositories, requiring immediate package removal, credential rotation, and persistence hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.