Bitwarden CLI Breach Ties to Checkmarx Supply Chain Campaign

1 min read
Source: The Hacker News
Bitwarden CLI Breach Ties to Checkmarx Supply Chain Campaign
Photo: The Hacker News
TL;DR Summary

Bitwarden CLI version 2026.4.0 was compromised via a malicious bw1.js distributed through npm during the Checkmarx supply chain campaign, with attackers exploiting a compromised GitHub Action in Bitwarden's CI/CD to steal tokens, secrets and credentials and exfiltrate them to audit.checkmarx.cx (and a fallback GitHub repository). The malware can inject malicious workflows to harvest secrets across downstream pipelines; Bitwarden says no end-user vault data was accessed and the issue was contained with the release deprecated. The incident is linked to TeamPCP and related to the Shai-Hulud activity; a CVE will be issued for this release.

Share this article

Reading Insights

Total Reads

0

Unique Readers

21

Time Saved

4 min

vs 5 min read

Condensed

90%

91194 words

Want the full story? Read the original article

Read on The Hacker News