Bitwarden
Disclosed Apr 23, 20265 months agoUnverified
Bitwarden CLI npm release trojanized to steal developer credentials
Version 2026.4.0 of the @bitwarden/cli npm package was published with credential-stealing code after a compromised GitHub Action in Bitwarden's CI pipeline, harvesting GitHub, npm and cloud tokens and SSH keys. Only the npm CLI was affected.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Apr 23, 2026 |
| Attack | Supply chain |
| Data exposed | Credentials and tokens, API keys |
| Sector | Tech · US |
| Status | Unverified: not yet confirmed by an official notice, a filing or the organization |
Sources
| Source | |
|---|---|
| Bitwarden CLI compromisedsocket.dev · News | News |
| Bitwarden CLI npm package compromised to steal developer credentialsbleepingcomputer.com · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Apr 23 |
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.