Post #1606328
2026-04-23 15:16 UTC
#Bitwarden CLI 2026.4.0 compromised in a supply chain attack.
https://socket.dev/blog/bitwarden-cli-compromised
Looks like the window was incredibly small and the impact minimal. A CVE is still being issued.
https://community.bitwarden.com/t/bitwarden-statement-on-checkmarx-supply-chain-incident/96127
> "The issue affected the npm distribution mechanism for the CLI during that limited window, not the integrity of the legitimate Bitwarden CLI codebase or stored vault data."
No need to panic, but I have a feeling we'll see a lot more of this. Recall XZ and SSH?
#security #cybersecurity
Replies (0)
No replies.