Bitwarden CLI npm package compromised to steal developer credentials
ID: f9088347-d7d8-5299-9982-c61b2844b56b
STIX ID: report--f9088347-d7d8-5299-9982-c61b2844b56b
Feed Name: Bleeping Computer
Bitwarden's npm CLI distribution was briefly compromised on April 22, 2026 when attackers published a malicious 2026.4.0 package that installed a loader which fetched an obfuscated credential-stealing payload; the malware collected npm, GitHub, SSH, and cloud credentials, encrypted them with AES-256-GCM, and exfiltrated data by creating public GitHub repositories (notably containing the string "Shai-Hulud:The Third Coming"); the payload also included self-propagation capabilities to abuse stolen npm credentials and target CI/CD environments. Bitwarden revoked the compromised access and deprecated the release, and affected users should assume credentials are compromised and rotate secrets — especially CI/CD and cloud keys.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
