SlowMist CISO: Bitwarden CLI was targeted by a supply chain attack, with malicious packages circulating for approximately 1.5 hours

robot
Abstract generation in progress

Deep Tide TechFlow news: On April 24, SlowMist CISO 23pds (@im23pds) disclosed that the password management tool Bitwarden CLI version 2026.4.0 was subjected to a Checkmarx supply-chain attack between 17:57 and 19:30 Eastern Time on April 22. During the attack, the attacker abused a GitHub Action in the Bitwarden CI/CD pipeline to temporarily distribute malicious packages via npm.

The official confirmed that Vault data was not leaked and that production systems were unaffected; only users who installed this version via npm during that time window were impacted. The official recommends that affected users immediately uninstall 2026.4.0, clear the npm cache, rotate sensitive credentials such as API Token and SSH Key, investigate abnormal activity on GitHub and in CI, and upgrade to the fixed version 2026.4.1.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin