CSIDB logo
Incident

Bitwarden

Incident posture

Attack window
Apr 2026
Location
United States of America
Status
Resolved
CIA posture
Available to members
Updated
2026-08-27 00:08

Linked entities

Victim
Bitwarden
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Undetermined
Disclosed
Apr 2026
Resolved
Undetermined

Summary

Bitwarden's command‑line interface was compromised as part of an ongoing Checkmarx supply chain campaign, with malicious code inserted into a package file via a compromised GitHub Action in the project’s CI/CD pipeline. The malicious version steals GitHub and npm tokens, SSH keys, environment files, shell history, GitHub Actions secrets and cloud credentials, encrypts the data with AES‑256‑GCM and exfiltrates it to audit.checkmarx[.]cx, falling back to a GitHub repository if needed. Stolen GitHub tokens are used to inject malicious Actions workflows that capture further secrets and push tainted package versions downstream. Researchers identified the string 'Shai‑Hulud: The Third Coming' in the malware and linked the activity to threat actor TeamPCP. The company confirmed the breach, stating that no end‑user data was accessed and that a CVE is being issued for the affected CLI release.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On April 23, 2026, researchers from JFrog and Socket reported that the Bitwarden CLI package version @bitwarden/[email protected] had been compromised as part of the ongoing Checkmarx supply chain campaign. The malicious code was located in a file named bw1.js within the package and was executed through a preinstall hook when the package was installed. This hook harvested a range of developer secrets, including GitHub and npm tokens, .ssh keys, .env files, shell history, GitHub Actions secrets, and cloud credentials, encrypting the stolen data with AES‑256‑GCM before exfiltrating it to the domain audit.checkmarx[.]cx, with a fallback mechanism that committed the data to a GitHub repository. If GitHub tokens were discovered, the malware used them to inject malicious GitHub Actions workflows into the victim’s repositories, thereby capturing additional CI/CD secrets and enabling further propagation.

The compromise allowed a single developer who had installed the tainted version to become an entry point for a broader supply chain attack, granting the attacker persistent workflow injection access to every CI/CD pipeline reachable via the stolen tokens. Threat actors were observed using the harvested npm credentials to push additional malicious versions of the Bitwarden CLI to the npm registry, thereby exposing downstream users to the same credential‑stealing payload. Socket noted that the attack followed the same GitHub Actions supply chain vector previously identified in the Checkmarx campaign, and OX Security identified the string 'Shai‑Hulud: The Third Coming' embedded in the malicious package, suggesting a continuation of an earlier attack series. The threat actor known as TeamPCP was suspected of being behind this particular incident, which targeted the Checkmarx ecosystem.

Bitwarden confirmed the incident, stating that the breach originated from a compromise of its npm distribution mechanism linked to the Checkmarx supply chain attack, while emphasizing that no end‑user data had been accessed or placed at risk. The company clarified that users who had not downloaded the affected package from npm during the compromise window remained unaffected. After completing a review of its internal environments, release paths, and related systems, Bitwarden reported that no additional products or environments showed signs of impact, and it announced that a CVE for Bitwarden CLI version 2026.4.0 was being issued in connection with the event.

Sources

Sources available to members: 1 source.

CSIDB