
Bitwarden CLI npm Package Compromised to Steal Developer Credentials
SecurityBitwardennpmsupply-chain-attackmalwarecredential-theftCLIdeveloper-security
Attackers compromised the official Bitwarden CLI by uploading a malicious @bitwarden/cli package to the npm registry, which contained a credential-stealing payload designed to exfiltrate developer credentials. The malicious package was capable of spreading to other projects through dependency chains. The incident involved the legitimate Bitwarden CLI tool, though no specific timeline or exact date of compromise was provided. No CVE ID was mentioned in relation to this attack. The primary impact was the potential theft of sensitive developer credentials, posing risks to affected systems and downstream projects.