<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

Bitwarden's CLI Tool Was Secretly Weaponized to Steal Cloud Credentials

Hackers hijack Bitwarden's CLI NPM package, stealing credentials from AWS, Azure, GitHub, and more. No user vault data exposed.
Content Team

Hackers compromised version 2026.4.0 of Bitwarden's CLI NPM package — downloaded over 250,000 times monthly — injecting malware that systematically steals credentials across AWS, Azure, GitHub, GCP, and more. The malicious code also hijacks victims' GitHub accounts to exfiltrate additional secrets, making stolen data potentially visible to anyone searching GitHub — not just the attackers. Bitwarden confirmed the breach but says no user vault data was exposed. The attack mirrors a recent hit on Checkmarx and shares code with the Shai-Hulud worm campaigns from 2024. Hacking group TeamPCP is suspected, though attribution remains complicated.

Source: SecurityWeek

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo