• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Cyber Security News

Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign

You are here: Home / General Cyber Security News / Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign
April 23, 2026

Bitwarden CLI has been compromised as part of the newly discovered and ongoing Checkmarx supply chain campaign, according to new findings from Socket.

“The affected package version appears to be @bitwarden/[email protected], and the malicious code was published in ‘bw1.js,’ a file included in the package contents,” the application security company said.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


“The attack appears to have leveraged a compromised GitHub Action in Bitwarden’s CI/CD pipeline, consistent with the pattern seen across other affected repositories in this campaign.”

In a post on X, JFrog said the rogue version of the package “steals GitHub/npm tokens, .ssh, .env, shell history, GitHub Actions and cloud secrets, then exfiltrates the data to private domains and as GitHub commits.”

Cybersecurity

While the malicious version is no longer available for download from npm, Socket said the compromise follows the same GitHub Actions supply chain vector identified in the Checkmarx campaign.

As part of the effort, threat actors have been found abusing stolen GitHub tokens to inject a new GitHub Actions workflow that captures secrets available to the workflow run, and uses harvested npm credentials to push malicious versions of the package to read the malware to downstream users.

It’s suspected that the threat actor known as TeamPCP is behind the latest attack aimed at Checkmarx. As of writing, TeamPCP’s X account has been suspended for violating the platform’s rules.

(This is a developing story. Please check for more details.)

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


Some parts of this article are sourced from:
thehackernews.com

Previous Post: «threatsday bulletin: $290m defi hack, macos lol abuse, proxysmart sim ThreatsDay Bulletin: $290M DeFi Hack, macOS LoL Abuse, ProxySmart SIM Farms +25 New Stories

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign
  • ThreatsDay Bulletin: $290M DeFi Hack, macOS LoL Abuse, ProxySmart SIM Farms +25 New Stories
  • [Webinar] Mythos Reality Check: Beating Automated Exploitation at AI Speed
  • Project Glasswing Proved AI Can Find the Bugs. Who’s Going to Fix Them?
  • China-Linked GopherWhisper Infects 12 Mongolian Government Systems with Go Backdoors
  • Vercel Finds More Compromised Accounts in Context.ai-Linked Breach
  • Apple Patches iOS Flaw That Stored Deleted Signal Notifications in FBI Forensic Case
  • Malicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply Chain
  • Self-Propagating Supply Chain Worm Hijacks npm Packages to Steal Developer Tokens
  • Harvester Deploys Linux GoGra Backdoor in South Asia Using Microsoft Graph API

Copyright © TheCyberSecurity.News, All Rights Reserved.