Bitwarden CLI Compromise Linked to Ongoing Checkmarx Supply Chain Campaign
ID: 77c8cbd3-01b4-57b5-9787-21c9f9ecb96f
STIX ID: report--77c8cbd3-01b4-57b5-9787-21c9f9ecb96f
Feed Name: Security Boulevard
Researchers discovered a malicious npm package (Bitwarden CLI v2026.4.0) deployed via an abused GitHub Action that replaced the legitimate preinstall/CLI with a custom loader which downloads a runtime and executes an obfuscated JavaScript infostealer. The payload targets developer and CI secrets (GitHub/npm tokens, SSH keys, cloud credentials, AI tooling configs), encrypts exfiltrated data with AES-256-GCM, and exfiltrates to a domain impersonating Checkmarx; the incident is tied to an ongoing supply-chain campaign attributed to TeamPCP/Shai-Hulud and was active for ~90 minutes before containment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
