Skip to content

Bitwarden CLI 2026.4.0 compromised in Checkmarx supply chain attack

devApr 23, 202674

Malicious code inserted via an abused GitHub Action in @bitwarden/[email protected] stole secrets and spread credential‑stealing malware.

3 sources