Home / Companies / Endor Labs / Blog / Post Details
Content Deep Dive

Inside the Bitwarden Software Supply Chain Attack (Shai-Hulud)

Blog post from Endor Labs

Post Details
Company
Date Published
Author
Kiran Raj
Word Count
3,621
Company Posts That Month
35
Language
English
Hacker News Points
-
Post removed?
No
Summary

Bitwarden's command-line interface (CLI) was compromised in a software supply chain attack when a malicious version, 2026.4.0, was briefly available on npm. Bitwarden, an open-source password manager used by many individuals and organizations, provides a CLI that can be integrated into CI/CD pipelines, making it a lucrative target for attackers. The attack leveraged a breach in Checkmarx's GitHub Actions, allowing the malicious CLI to harvest CI secrets and replicate itself in victims' npm projects. This incident highlights the vulnerabilities inherent in open-source software supply chains, emphasizing the need for software composition analysis and malicious package detection to prevent unauthorized access to sensitive data. The compromised version introduced obfuscated files and scripts to redirect execution paths and collect secrets, exfiltrating them to public GitHub repositories. The attack also featured a novel technique of using GitHub's commit-search API as a command-and-control channel and targeted authenticated AI coding assistants. Mitigation measures include uninstalling the compromised version, rotating credentials, and auditing systems for signs of the attack.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 19 1,821 338 111 +22%
AI Coding Assistant 3 1,480 382 153 +18%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.