Bitwarden CLI 2026.4.0 compromised in Checkmarx supply chain attack
devApr 23, 202661
Key Highlights
Bitwarden CLI version 2026.4.0 contained malicious code inserted through a GitHub Action.
Injected code exfiltrated environment secrets and pushed credential-stealing malware via npm.
Security teams tied the compromise to the Checkmarx supply chain campaign.