Bitwarden hit by network compromise
Incident
Summary
Hide ▲
Show ▼
Bitwarden's @bitwarden/cli distribution channel was compromised when a malicious package briefly appeared on npm, putting developers who installed it at risk of credential theft. The release was live only for a short window on April 22, 2026 before removal. Bitwarden said vault data and production systems were not compromised.
Related Happenings
AsyncAPI malicious npm package supply-chain malware
Malware Activity
H score21
First: 15.07.2026 18:37
Last: 15.07.2026 18:37
Sources 1
About this happening:
Malicious AsyncAPI npm releases pushed a remote access trojan and info-stealing payload into packages with more than 2.25 million weekly downloads, putting downstr...
AsyncAPI malicious npm package supply-chain malware
Malware ActivityAbout this happening: Malicious AsyncAPI npm releases pushed a remote access trojan and info-stealing payload into packages with more than 2.25 million weekly downloads, putting downstr...
AsyncAPI repositories and npm publishing workflow hit by network compromise
Incident
H score27
First: 15.07.2026 12:16
Last: 15.07.2026 12:16
Sources 1
About this happening:
The AsyncAPI npm publishing pipeline was compromised in a July 14 supply-chain attack that used the project’s normal GitHub Actions release path to publish trojani...
AsyncAPI repositories and npm publishing workflow hit by network compromise
IncidentAbout this happening: The AsyncAPI npm publishing pipeline was compromised in a July 14 supply-chain attack that used the project’s normal GitHub Actions release path to publish trojani...
Jscrambler hit by network compromise
Incident
H score15
First: 13.07.2026 22:44
Last: 13.07.2026 22:44
Sources 1
About this happening:
The Jscrambler npm package suffered an unauthorized publication of a malicious version that exposed developers to infostealer theft risk. The bad release stayed li...
Jscrambler hit by network compromise
IncidentAbout this happening: The Jscrambler npm package suffered an unauthorized publication of a malicious version that exposed developers to infostealer theft risk. The bad release stayed li...
Injective Labs SDK project GitHub repository hit by network compromise
Incident
H score21
First: 09.07.2026 23:10
Last: 09.07.2026 23:10
Sources 1
About this happening:
The Injective Labs SDK project suffered a GitHub repository compromise that let attackers publish a malicious @injectivelabs/sdk-ts v1.20.21 package, putting developer...
Injective Labs SDK project GitHub repository hit by network compromise
IncidentAbout this happening: The Injective Labs SDK project suffered a GitHub repository compromise that let attackers publish a malicious @injectivelabs/sdk-ts v1.20.21 package, putting developer...
Easy-day-js Mastra package-publishing campaign
Campaign
H score30
First: 17.06.2026 10:38
Last: 17.06.2026 10:38
Sources 1
About this happening:
The easy-day-js campaign mass-published more than 140 malicious npm packages across the @mastra/* namespace, creating broad supply-chain exposure for developers and bu...
Easy-day-js Mastra package-publishing campaign
CampaignAbout this happening: The easy-day-js campaign mass-published more than 140 malicious npm packages across the @mastra/* namespace, creating broad supply-chain exposure for developers and bu...
Timeline
-
23.04.2026 22:21 1 articles · 2mo ago
Malicious @bitwarden/cli release reaches npm
Exploitation ObservedAttackers published malicious @bitwarden/cli version 2026.4.0 to npm on April 22, 2026, apparently through a compromised GitHub Action in Bitwarden's CI/CD pipeline, and the package used bw_setup.js and bw1.js to load Bun and inject credential-stealing code into the CLI distribution.
Show sources
- Bitwarden CLI npm package compromised to steal developer credentials — www.bleepingcomputer.com — 23.04.2026 22:21
-
23.04.2026 22:21 2 articles · 2mo ago
Bitwarden confirms CLI npm compromise and analysts detail the payload
Technical Analysis UpdateBitwarden confirmed that the compromised npm distribution channel for the CLI package only affected users who downloaded the malicious version, revoked compromised access, deprecated the affected release, and said end user vault data and production systems were not compromised; Socket, JFrog, and OX Security said the payload used bw_setup.js and bw1.js to collect npm tokens, GitHub authentication tokens, SSH keys, and cloud credentials for AWS, Azure, and Google Cloud, encrypt the data with AES-256-GCM, and exfiltrate it through public GitHub repositories.
Show sources
- Bitwarden CLI npm package compromised to steal developer credentials — www.bleepingcomputer.com — 23.04.2026 22:21
- Bitwarden CLI npm package compromised to steal developer credentials — www.bleepingcomputer.com — 23.04.2026 22:21