Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Bitwarden CLI npm package compromised to steal developer credentials
    Cybersecurity

    Bitwarden CLI npm package compromised to steal developer credentials

    adminBy adminApril 24, 2026No Comments4 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Bitwarden
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Bitwarden

    Updated with further information from Bitwarden.

    The Bitwarden CLI was briefly compromised after attackers uploaded a malicious @bitwarden/cli package to npm containing a credential-stealing payload capable of spreading to other projects.

    According to reports by Socket, JFrog, and OX Security, the malicious package was distributed as version 2026.4.0 and remained available between 5:57 PM and 7:30 PM ET on April 22, 2026, before being removed.

    image

    Bitwarden confirmed the incident, stating that the breach affected only its npm distribution channel for the CLI npm package and only those who downloaded the malicious version. 

    “The investigation found no evidence that end user vault data was accessed or at risk, or that production data or production systems were compromised. Once the issue was detected, compromised access was revoked, the malicious npm release was deprecated, and remediation steps were initiated immediately,” Bitwarden shared in a statement.

    “The issue affected the npm distribution mechanism for the CLI during that limited window, not the integrity of the legitimate Bitwarden CLI codebase or stored vault data.”

    Bitwarden says it revoked the compromised access and deprecated the affected CLI npm release.

    The Bitwarden supply chain attack

    According to Socket, threat actors appear to have used a compromised GitHub Action in Bitwarden’s CI/CD pipeline to inject malicious code into the CLI npm package.

    According to JFrog, the package was modified so that the preinstall script and the CLI entry point use a custom loader named bw_setup.js, which checks for the Bun runtime and, if it does not exist, downloads it.

    The loader then uses the Bun runtime to launch an obfuscated JavaScript file named bw1.js, which acts as credential-stealing malware.

    Loader executing the malicious bw1.js file
    Loader executing the malicious bw1.js file
    Source: Jfrog

    Once executed, the malware collects a wide range of secrets from infected systems, including npm tokens, GitHub authentication tokens, SSH keys, and cloud credentials for AWS, Azure, and Google Cloud.

    The malware encrypts the collected data using AES-256-GCM and exfiltrates it by creating public GitHub repositories under the victim’s account, where the encrypted data is stored.

    OX Security says that these created repositories contain the string “Shai-Hulud: The Third Coming,” a reference to previous npm supply chain attacks that used a similar method and text string when exfiltrating stolen data.

    Data exfiltration repository with a
    Data exfiltration repository with a “Shai-Hulud: The Third Coming” string
    Source: OX Security

    The malware also features self-propagation capabilities, with OX Security reporting that it can use stolen npm credentials to identify packages the victim can modify and inject them with malicious code.

    Socket also observed that the payload targets CI/CD environments and attempts to harvest secrets that can be reused to expand the attack.

    The attack comes after Checkmarx disclosed a separate supply chain incident yesterday that impacts its KICS Docker images, GitHub Actions, and developer extensions.

    While it is not known exactly how attackers gained access, Bitwarden told BleepingComputer the incident was linked to the Checkmarx supply chain attack, with a compromised Checkmarx-related development tool enabling abuse of the npm delivery path for the CLI during a limited time window.

    Socket told BleepingComputer that there are overlapping indicators between the Checkmarx breach and this attack.

    “The connection is at the malware and infrastructure level. In the Bitwarden case, the malicious payload uses the same audit.checkmarx[.]cx/v1/telemetry endpoint that appeared in the Checkmarx incident. It also uses the same __decodeScrambled obfuscation routine with the seed 0x3039, and shows the same general pattern of credential theft, GitHub-based exfiltration, and supply chain propagation behavior,” Socket told BleepingComputer.

    “That overlap goes beyond a superficial resemblance. The Bitwarden payload contains the same kind of embedded gzip+base64 components we saw in the earlier malware, including tooling for credential collection and downstream abuse.”

    Both campaigns have been linked to a threat actor known as TeamPCP, who previously targeted developer packages in the massive Trivy and LiteLLM supply chain attacks.

    Developers who installed the affected version should treat their systems and credentials as compromised and rotate all exposed credentials, especially those used for CI/CD pipelines, cloud storage, and developer environments.

    Update 4/23/26: Updated the story with information from Bitwarden confirming the incident was linked to the Checkmarx supply chain attack.


    article image

    AI chained four zero-days into one exploit that bypassed both renderer and OS sandboxes. A wave of new exploits is coming.

    At the Autonomous Validation Summit (May 12 & 14), see how autonomous, context-rich validation finds what’s exploitable, proves controls hold, and closes the remediation loop.

    Claim Your Spot

    Bitwarden CLI Compromised Credentials developer npm Package steal
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleGoogle expands Demand Gen tools to drive faster YouTube conversions
    Next Article There’s a sneaky way to watch Half Man for free
    admin
    • Website

    Related Posts

    China-Backed Hackers Are Industrializing Botnets

    April 24, 2026

    LMDeploy CVE-2026-33626 Flaw Exploited Within 13 Hours of Disclosure

    April 24, 2026

    OpenAI’s GPT-5.5 is out with expanded cybersecurity safeguards

    April 24, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    The Pixel 10’s new display filter is fantastic, except for two big flaws

    April 24, 2026

    China-Backed Hackers Are Industrializing Botnets

    April 24, 2026

    5 lessons from delivering bad SEO news to executives

    April 24, 2026

    LMDeploy CVE-2026-33626 Flaw Exploited Within 13 Hours of Disclosure

    April 24, 2026
    Categories
    • Blogging (67)
    • Cybersecurity (1,483)
    • Privacy & Online Earning (181)
    • SEO & Digital Marketing (910)
    • Tech Tools & Mobile / Apps (1,770)
    • WiFi / Internet & Networking (243)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    The Pixel 10’s new display filter is fantastic, except for two big flaws

    April 24, 2026

    China-Backed Hackers Are Industrializing Botnets

    April 24, 2026

    5 lessons from delivering bad SEO news to executives

    April 24, 2026
    Most Popular
    • The Pixel 10’s new display filter is fantastic, except for two big flaws
    • China-Backed Hackers Are Industrializing Botnets
    • 5 lessons from delivering bad SEO news to executives
    • LMDeploy CVE-2026-33626 Flaw Exploited Within 13 Hours of Disclosure
    • Airtel Xstream Play: 25+ OTTs 1.117.2 by Airtel
    • OpenAI’s GPT-5.5 is out with expanded cybersecurity safeguards
    • The Real Reason Your SEO Team Hasn’t Made The AI Transition Yet
    • These UAG cases fix the biggest issue with the Galaxy S26 Ultra
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.