Inside the Bitwarden Software Supply Chain Attack (Shai-Hulud)
Blog post from Endor Labs
Bitwarden's command-line interface (CLI) was compromised in a software supply chain attack when a malicious version, 2026.4.0, was briefly available on npm. Bitwarden, an open-source password manager used by many individuals and organizations, provides a CLI that can be integrated into CI/CD pipelines, making it a lucrative target for attackers. The attack leveraged a breach in Checkmarx's GitHub Actions, allowing the malicious CLI to harvest CI secrets and replicate itself in victims' npm projects. This incident highlights the vulnerabilities inherent in open-source software supply chains, emphasizing the need for software composition analysis and malicious package detection to prevent unauthorized access to sensitive data. The compromised version introduced obfuscated files and scripts to redirect execution paths and collect secrets, exfiltrating them to public GitHub repositories. The attack also featured a novel technique of using GitHub's commit-search API as a command-and-control channel and targeted authenticated AI coding assistants. Mitigation measures include uninstalling the compromised version, rotating credentials, and auditing systems for signs of the attack.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 19 | 1,821 | 338 | 111 | +22% |
| AI Coding Assistant | 3 | 1,480 | 382 | 153 | +18% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.