Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign
ID: cae9aaf3-fd4e-50f7-8ff6-5400f8d5efef
STIX ID: report--cae9aaf3-fd4e-50f7-8ff6-5400f8d5efef
Feed Name: The Hacker News
Threat Score
A malicious npm release of @bitwarden/cli (2026.4.0) delivered a preinstall-hook credential stealer (bw1.js) that targeted developer, CI/GitHub, and cloud secrets, encrypted them with AES-256-GCM, and exfiltrated data to audit.checkmarx.cx and fallback GitHub repositories; stolen GitHub tokens were used to inject malicious Actions workflows and publish additional malicious packages as part of an ongoing Checkmarx-linked supply-chain campaign attributed to TeamPCP.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
