Netcrook Logo

Tag: Bitwarden

8 article(s)

Bitwarden CLI Supply Chain Attack: Malicious Update Steals Developer Secrets

24 Apr 2026 news

A malicious version of Bitwarden CLI was distributed via npm, enabling attackers to steal credentials from developers and CI/CD pipelines. The breach highlights growing risks in software supply chains and the need for rapid incident response.

#Bitwarden | #Supply Chain Attack | #Credential Exfiltration

TeamPCP Exploits Bitwarden CLI and Dependabot in Shai-Hulud Malware Supply Chain Attack

24 Apr 2026 news

A trusted GitHub automation and a popular open-source password manager became the perfect storm for TeamPCP’s Shai-Hulud malware campaign, stealing credentials and poisoning AI coding tools from inside the developer supply chain.

#TeamPCP | #Supply Chain Attack | #Bitwarden

Bitwarden CLI Breach: Dune-Themed Hackers Exploit GitHub Actions in Sophisticated Supply Chain Attack

24 Apr 2026 news

A dramatic supply chain attack hit Bitwarden CLI’s npm package, using GitHub Actions to inject credential-stealing malware and exfiltrate secrets to Dune-themed public repositories. Here’s how it happened and what it means for open source security.

#Bitwarden | #supply chain attack | #GitHub Actions

Bitwarden CLI Breach: GitHub Actions Used in Dune-Themed Supply Chain Attack

24 Apr 2026 news

Attackers exploited Bitwarden’s CI/CD pipeline with a rogue GitHub Action, injecting malware into the @bitwarden/cli npm package. The breach harvests credentials and exfiltrates them through Dune-themed public repositories, highlighting new risks in software supply chains.

#Bitwarden | #Supply Chain Attack | #Credential Harvesting

Bitwarden npm CLI Breach: Supply Chain Attack Exposes Developer Secrets

23 Apr 2026 news

Bitwarden’s npm CLI package was briefly hijacked in April 2026, allowing attackers to steal credentials from developers. The incident, linked to the TeamPCP group and Checkmarx breach, underscores the growing threat of supply chain attacks in the software ecosystem.

#Bitwarden | #Supply chain attack | #Credential theft

Bitwarden CLI Breach Unveils New Supply Chain Security Risks

23 Apr 2026 news

Bitwarden’s CLI npm package was briefly hijacked in a supply chain attack, exposing credentials and secrets via a compromised GitHub Actions workflow. Investigators link the incident to the Checkmarx campaign, highlighting new threats to trusted developer tools.

#Bitwarden | #Supply Chain Attack | #Cybersecurity

Bitwarden Launches Passkey Login for Windows 11: A Passwordless Future?

05 Mar 2026 news 🌍 North America

Bitwarden introduces passkey login for Windows 11, allowing users to authenticate without passwords. This move leverages cryptographic credentials for enhanced security and marks a new chapter in passwordless authentication.

#Bitwarden | #Passkey | #Windows 11

Bitwarden’s Cupid Vault: Secure Password Sharing or a New Cybersecurity Risk?

13 Feb 2026 news

Bitwarden’s Cupid Vault lets free users securely share passwords with one trusted partner. Our feature investigates how it works, the technical safeguards, and the risks that come with digital intimacy.

#Bitwarden | #Cupid Vault | #password sharing