Bitwarden CLI Supply Chain Attack Puts Crypto Wallet Keys at Risk

Source Beincrypto

Attackers hijacked password manager Bitwarden’s CLI version 2026.4.0 through a compromised GitHub Action, publishing a malicious npm package that actively steals crypto wallet data and developer credentials.

Security firm Socket discovered the breach on April 23 and linked it to the ongoing TeamPCP supply chain campaign. The rogue npm version has since been pulled.

Malware Target Risks Crypto Wallets and CI/CD Secrets

The malicious payload, embedded in a file called bw1.js, ran during package installation and harvested GitHub and npm tokens, SSH keys, environment variables, shell history, and cloud credentials.

TeamPCP’s broader campaign is separately confirmed to target crypto wallet data, including MetaMask, Phantom, and Solana wallet files.

According to JFrog, the stolen data was exfiltrated to attacker-controlled domains and committed back to GitHub repositories as a persistence mechanism.

Many crypto teams use the Bitwarden CLI in automated CI/CD pipelines for secrets injection and deployments. Any workflows that ran the compromised version may have exposed high-value wallet keys and exchange API credentials.

Security researcher Adnan Khan noted this is the first known compromise of a package using npm’s trusted publishing mechanism, which was designed to eliminate long-lived tokens.

What Affected Users Should Do

Socket recommends that anyone who installed @bitwarden/cli version 2026.4.0 rotate every exposed secret immediately.

Users should downgrade to version 2026.3.0 or switch to official signed binaries from Bitwarden’s website.

TeamPCP has chained similar attacks against Trivy, Checkmarx, and LiteLLM since March 2026, targeting developer tools that sit deep in build pipelines.

Bitwarden’s core vault remains unaffected. Only the CLI build process was compromised.

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Analyst Predicts Bitcoin Price Is Going To $200,000, Reveals When To BuyBitcoin is back in a place where bold upside calls are starting to circulate again, and while short-term sentiment is still mixed, one analyst believes the cryptocurrency is setting up for a powerful
Author  NewsBTC
13 hours ago
Bitcoin is back in a place where bold upside calls are starting to circulate again, and while short-term sentiment is still mixed, one analyst believes the cryptocurrency is setting up for a powerful
placeholder
XRP Network Heats Up After 75 Million Transfer Drives Activity HigherWhile market observers often watch the price of tokens, the real story right now is happening in the background of the XRP Ledger. Institutional interest in XRP Spot ETFs is climbing, with more than
Author  NewsBTC
13 hours ago
While market observers often watch the price of tokens, the real story right now is happening in the background of the XRP Ledger. Institutional interest in XRP Spot ETFs is climbing, with more than
placeholder
Bitcoin Bulls Rebuild As Futures Metric Hits 4-Month HighBitcoin’s derivatives market is showing signs of a fresh bullish rebuild, according to a new morning brief from on-chain analyst Axel Adler Jr., who said a rising Bitcoin Positioning Index
Author  NewsBTC
14 hours ago
Bitcoin’s derivatives market is showing signs of a fresh bullish rebuild, according to a new morning brief from on-chain analyst Axel Adler Jr., who said a rising Bitcoin Positioning Index
placeholder
Tesla posts 16% revenue growth to $22.4 billion, misses Wall Street estimatesTesla on Wednesday posted 16% revenue growth in the first quarter of 2026, bringing in $22.39 billion and slightly missing the $22.64 billion Wall Street expected. In the earnings report, Tesla said adjusted earnings per share came in at 41 cents, ahead of the 37 cents analysts polled by LSEG were looking for. The TSLA […]
Author  Cryptopolitan
14 hours ago
Tesla on Wednesday posted 16% revenue growth in the first quarter of 2026, bringing in $22.39 billion and slightly missing the $22.64 billion Wall Street expected. In the earnings report, Tesla said adjusted earnings per share came in at 41 cents, ahead of the 37 cents analysts polled by LSEG were looking for. The TSLA […]
placeholder
A 43% Projection Is Calling the Gold vs Silver Winner as Oil CoolsThe gold vs silver divergence has widened sharply this month. Silver (XAG/USD) is up 15.47% against gold’s (XAU/USD) 6% gain as Brent crude slides below $99 on continuing de-escalation talks.The gap i
Author  Beincrypto
14 hours ago
The gold vs silver divergence has widened sharply this month. Silver (XAG/USD) is up 15.47% against gold’s (XAU/USD) 6% gain as Brent crude slides below $99 on continuing de-escalation talks.The gap i
goTop
quote