logo

Bitwarden CLI Hijacked in npm Supply Chain Attack Linked to TeamPCP & Checkmarx Breach

ID: ca90b347-8eb3-5c5c-ac9b-a59cb81ee6c8

STIX ID: report--ca90b347-8eb3-5c5c-ac9b-a59cb81ee6c8

Feed Name: SOCRadar Blog

Threat Score
90/100

Date Published: 2026-04-24

Date Updated: 2026-04-30

Author: Yağmur Ernalbant

...
...

A malicious Bitwarden CLI npm release (v2026.4.0) circulated for roughly 90 minutes on April 22, 2026; it replaced the legitimate CLI entry points with a Bun runtime loader and an obfuscated infostealer that collected SSH keys, .npmrc, cloud credentials, GitHub tokens, CI/CD secrets, and AI/MCP tooling keys, exfiltrating data to audit.checkmarx.cx (94.154.172.43) using hybrid RSA/AES-GCM encryption and falling back to staged GitHub repositories; researchers attribute the campaign to TeamPCP and link it to a broader Checkmarx supply-chain compromise, while Bitwarden revoked access, deprecated the malicious release, and published remediation guidance including token rotation and network blocks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.