Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign
Blog post from Socket
Researchers have identified a security breach in the Bitwarden CLI, part of the ongoing Checkmarx supply chain campaign, affecting more than 10 million users and over 50,000 businesses. The breach involved the malicious version @bitwarden/cli2026.4.0, where the compromised code was found in the bw1.js file, exploiting a GitHub Action within Bitwarden’s CI/CD pipeline. The attack used tactics similar to other incidents in the Checkmarx campaign, with exfiltration occurring through methods such as GitHub API and npm registry. The compromise, which only affects the npm package for the CLI, has led to unauthorized credential harvesting and publishing of affected repositories. The attack features a unique ideological branding, indicating either a different operator using shared infrastructure or an evolution in the campaign's strategy. Organizations are advised to treat this as a credential exposure event, remove the compromised package, rotate exposed credentials, and review their systems for unauthorized activities and changes. The investigation is ongoing, with detailed findings and remediation guidance to be released by Socket's security research team.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 3 | 1,821 | 338 | 111 | +22% |
| MCP | 2 | 6,108 | 613 | 170 | +36% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.