BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Bitwarden CLI Compromised by Checkmarx Supply Chain Attack

Bitwarden CLI compromised, steals secrets via hacked npm package in supply chain attack.

  • The official Bitwarden CLI package on npm was compromised, distributing a malicious version that steals credentials and secrets.
  • The supply chain attack used a hacked GitHub Actions workflow, a method consistent with the broader Checkmarx campaign, and targeted developer AI tool configurations.
  • While the malicious package has been deprecated, a single compromised developer installation could enable attackers to persistently inject malware into CI/CD pipelines.
  • Security researchers detected a reference to “Shai-Hulud: The Third Coming” within the malware, suggesting this is a new phase of a known campaign.
  • Bitwarden confirmed the incident was limited to its npm distribution mechanism and stated no end-user vault data was accessed or at risk.

The Bitwarden CLI became the latest victim in an ongoing supply chain campaign, with a malicious version published on April 22, 2026, according to new findings shared by JFrog and Socket. This version, labeled @bitwarden/cli@2026.4.0, contained code designed to exfiltrate sensitive developer data to attackers.

- Advertisement -

The attack appears to have leveraged a compromised GitHub Action in Bitwarden‘s CI/CD pipeline, consistent with the pattern seen across other affected repositories in this campaign. Consequently, the rogue package included a preinstall hook that executed data-stealing malware.

Data including GitHub and npm tokens, .ssh keys, and cloud secrets was exfiltrated to a domain impersonating Checkmarx. However, if this primary method failed, the stolen information was sent to a GitHub repository as a fallback.

The malware specifically targeted configurations for AI coding tools like Claude and Cursor. Meanwhile, if GitHub tokens were found, they were weaponized to inject malicious workflows into other repositories, as detailed in a blog post by Socket.

Security researcher Adnan Khan noted the threat actor used a malicious workflow for publication. “I believe this is the first time a package using NPM trusted publishing has been compromised,” Khan added.

- Advertisement -

OX Security said it identified the string “Shai-Hulud: The Third Coming” in the package, suggesting this is likely the next phase of the supply chain attack campaign. Interestingly, the malware is designed to quit execution on systems if their locale corresponds to Russia.

Bitwarden confirmed the incident stemmed from the compromise of its npm distribution mechanism. The company emphasized that no end-user vault data was accessed or at risk, and the malicious npm release was deprecated shortly after detection.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Ethereum Nears $2,000 As Market-Wide Correction Deepens

Ethereum (ETH) is facing a steep correction, falling 2.9% in the last 24 hours...

Bitcoin Depot Files Bankruptcy, Shuts Down ATM Network

Bitcoin Depot, North America's largest Bitcoin ATM operator, has filed for Chapter 11 bankruptcy...

Oil Inflation Fears Cloud Ethereum’s Tokenization Story

Fundstrat's Tom Lee identifies surging oil prices, with WTI crude above $106, as Ethereum's...

Kraken AI layoffs push US IPO to 2027

Cryptocurrency exchange Kraken has reportedly laid off approximately 150 employees, attributing the move to...

Crypto Market Plunges, $660M Liquidated in 24 Hours

Bitcoin has plunged to near $76,000, triggering over $660 million in market liquidations.Higher inflation,...

Must Read

How Much Money Do You Need To Start In Crypto?

TL;DR -If you are wondering How Much Money Do You Need To Start In Crypto, note that is less than you are probably thinking....
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading