logo

TeamPCP Hijacks Bitwarden CLI, Uses Dependabot to Deploy Shai-Hulud Malware

ID: 4e57831c-d2b7-5def-af0a-c009676e43af

STIX ID: report--4e57831c-d2b7-5def-af0a-c009676e43af

Feed Name: HackRead

Threat Score
82/100

Date Published: 2026-04-24

Date Updated: 2026-04-24

Author: Deeba Ahmed

...
...

Researchers disclosed that on April 20–22, 2026 the TeamPCP group compromised the @bitwarden/cli tool and deployed a worm called Shai-Hulud (CanisterSprawl). The attackers used a trojanized checkmarx/kics Docker image which Dependabot automatically pulled in CI to execute payloads with access to repository secrets, exfiltrated encrypted credential blobs via victims’ GitHub repositories, used GitHub commits as a fallback C2, and injected persistence into ~/.bashrc and ~/.zshrc to target developer workflows and AI coding assistants.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.