The Butlerian Jihad: Compromised Bitwarden CLI Deploys npm Worm, Poisons AI Assistants, and Dumps GitHub Secrets
ID: 25c8ad0e-b31b-5831-bf3b-8eb915e14e51
STIX ID: report--25c8ad0e-b31b-5831-bf3b-8eb915e14e51
Feed Name: Security Boulevard
**Executive summary:** A malicious supply-chain package impersonating @bitwarden/cli (v2026.4.0) was published to npm and delivered a sophisticated multi-component attack: credential harvesting (cloud keys, SSH, git, AI tool configs), an npm self-propagating worm that republished downstream packages, injection of a GitHub Actions workflow to dump CI/CD secrets, a runner memory dumper, and a novel AI assistant poisoning technique that appends an invisible manifesto to shell config files so AI tools ingest malicious context; the report provides technical analysis, indicators of compromise, and mitigation steps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
