Malicious Bitwarden CLI on npm Backdoored Installers for 93 Minutes

robot
Abstract generation in progress

A malicious Bitwarden CLI package appeared on npm under the official package name for 93 minutes and delivered a backdoored release to installers. JFrog said the payload targeted GitHub tokens, npm tokens, SSH keys, shell history, cloud credentials, GitHub Actions secrets, and AI tooling configuration files. Bitwarden said it found no evidence that attackers accessed end-user vault data or compromised production systems.

This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin