Find notable cyber news and cases, enriched with sources, timelines, and signals.

Bitwarden hit by network compromise

Incident
First reported
Last updated
Happening score
H score 34
1 unique sources, 1 articles

Summary

Hide ▲

Bitwarden's @bitwarden/cli distribution channel was compromised when a malicious package briefly appeared on npm, putting developers who installed it at risk of credential theft. The release was live only for a short window on April 22, 2026 before removal. Bitwarden said vault data and production systems were not compromised.

Related Happenings

AsyncAPI malicious npm package supply-chain malware

Malware Activity
H score21 First: 15.07.2026 18:37 Last: 15.07.2026 18:37 Sources 1

About this happening: Malicious AsyncAPI npm releases pushed a remote access trojan and info-stealing payload into packages with more than 2.25 million weekly downloads, putting downstr...

AsyncAPI repositories and npm publishing workflow hit by network compromise

Incident
H score27 First: 15.07.2026 12:16 Last: 15.07.2026 12:16 Sources 1

About this happening: The AsyncAPI npm publishing pipeline was compromised in a July 14 supply-chain attack that used the project’s normal GitHub Actions release path to publish trojani...

Jscrambler hit by network compromise

Incident
H score15 First: 13.07.2026 22:44 Last: 13.07.2026 22:44 Sources 1

About this happening: The Jscrambler npm package suffered an unauthorized publication of a malicious version that exposed developers to infostealer theft risk. The bad release stayed li...

Injective Labs SDK project GitHub repository hit by network compromise

Incident
H score21 First: 09.07.2026 23:10 Last: 09.07.2026 23:10 Sources 1

About this happening: The Injective Labs SDK project suffered a GitHub repository compromise that let attackers publish a malicious @injectivelabs/sdk-ts v1.20.21 package, putting developer...

Easy-day-js Mastra package-publishing campaign

Campaign
H score30 First: 17.06.2026 10:38 Last: 17.06.2026 10:38 Sources 1

About this happening: The easy-day-js campaign mass-published more than 140 malicious npm packages across the @mastra/* namespace, creating broad supply-chain exposure for developers and bu...

Timeline

  1. 23.04.2026 22:21 1 articles · 2mo ago

    Malicious @bitwarden/cli release reaches npm

    Exploitation Observed

    Attackers published malicious @bitwarden/cli version 2026.4.0 to npm on April 22, 2026, apparently through a compromised GitHub Action in Bitwarden's CI/CD pipeline, and the package used bw_setup.js and bw1.js to load Bun and inject credential-stealing code into the CLI distribution.

    Show sources
  2. 23.04.2026 22:21 2 articles · 2mo ago

    Bitwarden confirms CLI npm compromise and analysts detail the payload

    Technical Analysis Update

    Bitwarden confirmed that the compromised npm distribution channel for the CLI package only affected users who downloaded the malicious version, revoked compromised access, deprecated the affected release, and said end user vault data and production systems were not compromised; Socket, JFrog, and OX Security said the payload used bw_setup.js and bw1.js to collect npm tokens, GitHub authentication tokens, SSH keys, and cloud credentials for AWS, Azure, and Google Cloud, encrypt the data with AES-256-GCM, and exfiltrate it through public GitHub repositories.

    Show sources