logo

Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign

ID: cae9aaf3-fd4e-50f7-8ff6-5400f8d5efef

STIX ID: report--cae9aaf3-fd4e-50f7-8ff6-5400f8d5efef

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-04-23

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

A malicious npm release of @bitwarden/cli (2026.4.0) delivered a preinstall-hook credential stealer (bw1.js) that targeted developer, CI/GitHub, and cloud secrets, encrypted them with AES-256-GCM, and exfiltrated data to audit.checkmarx.cx and fallback GitHub repositories; stolen GitHub tokens were used to inject malicious Actions workflows and publish additional malicious packages as part of an ongoing Checkmarx-linked supply-chain campaign attributed to TeamPCP.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.