logo

Bitwarden CLI npm package compromised to steal developer credentials

ID: f9088347-d7d8-5299-9982-c61b2844b56b

STIX ID: report--f9088347-d7d8-5299-9982-c61b2844b56b

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2026-04-23

Date Updated: 2026-04-23

Author: Lawrence Abrams

...
...

Bitwarden's npm CLI distribution was briefly compromised on April 22, 2026 when attackers published a malicious 2026.4.0 package that installed a loader which fetched an obfuscated credential-stealing payload; the malware collected npm, GitHub, SSH, and cloud credentials, encrypted them with AES-256-GCM, and exfiltrated data by creating public GitHub repositories (notably containing the string "Shai-Hulud:The Third Coming"); the payload also included self-propagation capabilities to abuse stolen npm credentials and target CI/CD environments. Bitwarden revoked the compromised access and deprecated the release, and affected users should assume credentials are compromised and rotate secrets — especially CI/CD and cloud keys.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.