Skip to content

Bitwarden CLI 2026.4.0 compromised in Checkmarx supply chain attack

devApr 23, 202675

Attackers injected malicious code into the Bitwarden CLI npm package @bitwarden/cli@2026.4.0 by abusing a GitHub Action in Bitwarden's CI/CD pipeline. The compromised release exfiltrated secrets from build environments and delivered credential‑stealing malware to downstream users. Bitwarden's security team discovered the compromise on April 23 and linked it to the ongoing Checkmarx supply‑chain campaign. The incident threatens exposed API keys and crypto wallet credentials for projects that used the CLI and highlights attackers targeting CI/CD workflows.

3 sources