Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign

Blog post from Socket

Post Details
Company
Date Published
Author
Socket Research Team
Word Count
884
Company Posts That Month
32
Language
English
Hacker News Points
-
Post removed?
No
Summary

Researchers have identified a security breach in the Bitwarden CLI, part of the ongoing Checkmarx supply chain campaign, affecting more than 10 million users and over 50,000 businesses. The breach involved the malicious version @bitwarden/cli2026.4.0, where the compromised code was found in the bw1.js file, exploiting a GitHub Action within Bitwarden’s CI/CD pipeline. The attack used tactics similar to other incidents in the Checkmarx campaign, with exfiltration occurring through methods such as GitHub API and npm registry. The compromise, which only affects the npm package for the CLI, has led to unauthorized credential harvesting and publishing of affected repositories. The attack features a unique ideological branding, indicating either a different operator using shared infrastructure or an evolution in the campaign's strategy. Organizations are advised to treat this as a credential exposure event, remove the compromised package, rotate exposed credentials, and review their systems for unauthorized activities and changes. The investigation is ongoing, with detailed findings and remediation guidance to be released by Socket's security research team.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 3 1,821 338 111 +22%
MCP 2 6,108 613 170 +36%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.