CriticalSecurity & Privacy
Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign
Bitwarden CLI version 2026.4.0 was compromised via a malicious GitHub Action in the CI/CD pipeline as part of the broader Checkmarx supply chain campaign, affecting a password manager used by over 10 million individuals and 50,000 businesses. The attack harvested credentials (GitHub tokens, AWS/Azure/GCP credentials, SSH keys, npm tokens) and enabled supply chain propagation through npm token theft and repository injection. CIOs must immediately treat this as a credential exposure and CI/CD compromise event, requiring rapid rotation of all secrets that may have touched the affected build environment and forensic review of GitHub and npm activity for unauthorized access.
Hacker News3 min read

Bitwarden CLI version 2026.4.0 was compromised via a malicious GitHub Action in the CI/CD pipeline as part of the broader Checkmarx supply chain campaign, affecting a password manager used by over 10 million individuals and 50,000 businesses. The attack harvested credentials (GitHub tokens, AWS/Azure/GCP credentials, SSH keys, npm tokens) and enabled supply chain propagation through npm token theft and repository injection. CIOs must immediately treat this as a credential exposure and CI/CD compromise event, requiring rapid rotation of all secrets that may have touched the affected build environment and forensic review of GitHub and npm activity for unauthorized access.