Skip to content

Bitwarden

Disclosed Apr 23, 20265 months agoUnverified

Bitwarden CLI npm release trojanized to steal developer credentials

Version 2026.4.0 of the @bitwarden/cli npm package was published with credential-stealing code after a compromised GitHub Action in Bitwarden's CI pipeline, harvesting GitHub, npm and cloud tokens and SSH keys. Only the npm CLI was affected.

What is known

People affectedNot stated in the sources we have
DisclosedApr 23, 2026
AttackSupply chain
Data exposedCredentials and tokens, API keys
SectorTech · US
StatusUnverified: not yet confirmed by an official notice, a filing or the organization

Sources

Source
Bitwarden CLI compromisedsocket.dev · News
Bitwarden CLI npm package compromised to steal developer credentialsbleepingcomputer.com · News

Notices filed

WhereFiledPeople
ResearchtotalApr 23
History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.

Everything about Bitwarden

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.