Bitwarden CLI Supply Chain Attack Puts Crypto Wallet Keys at Risk

Source Beincrypto

Attackers hijacked password manager Bitwarden’s CLI version 2026.4.0 through a compromised GitHub Action, publishing a malicious npm package that actively steals crypto wallet data and developer credentials.

Security firm Socket discovered the breach on April 23 and linked it to the ongoing TeamPCP supply chain campaign. The rogue npm version has since been pulled.

Malware Target Risks Crypto Wallets and CI/CD Secrets

The malicious payload, embedded in a file called bw1.js, ran during package installation and harvested GitHub and npm tokens, SSH keys, environment variables, shell history, and cloud credentials.

TeamPCP’s broader campaign is separately confirmed to target crypto wallet data, including MetaMask, Phantom, and Solana wallet files.

According to JFrog, the stolen data was exfiltrated to attacker-controlled domains and committed back to GitHub repositories as a persistence mechanism.

Many crypto teams use the Bitwarden CLI in automated CI/CD pipelines for secrets injection and deployments. Any workflows that ran the compromised version may have exposed high-value wallet keys and exchange API credentials.

Security researcher Adnan Khan noted this is the first known compromise of a package using npm’s trusted publishing mechanism, which was designed to eliminate long-lived tokens.

What Affected Users Should Do

Socket recommends that anyone who installed @bitwarden/cli version 2026.4.0 rotate every exposed secret immediately.

Users should downgrade to version 2026.3.0 or switch to official signed binaries from Bitwarden’s website.

TeamPCP has chained similar attacks against Trivy, Checkmarx, and LiteLLM since March 2026, targeting developer tools that sit deep in build pipelines.

Bitwarden’s core vault remains unaffected. Only the CLI build process was compromised.

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Silver Price Forecast: XAG/USD plummets below $76 as oil price posts fresh weekly highSilver price (XAG/USD) is down almost 2.3% to near $76.00 during the European trading session on Thursday. The white metal faces selling pressure as oil prices extends its winning streak for the third trading day on Thursday.
Author  FXStreet
6 hours ago
Silver price (XAG/USD) is down almost 2.3% to near $76.00 during the European trading session on Thursday. The white metal faces selling pressure as oil prices extends its winning streak for the third trading day on Thursday.
placeholder
WTI sticks to positive bias above $92.00 amid Middle East tensionsWest Texas Intermediate (WTI) – the benchmark US Crude Oil price – fades an Asian session spike to the $95.80-$95.85 area, or a one-and-a-half-week top, and retreats to the lower end of its daily range in the last hour.
Author  FXStreet
15 hours ago
West Texas Intermediate (WTI) – the benchmark US Crude Oil price – fades an Asian session spike to the $95.80-$95.85 area, or a one-and-a-half-week top, and retreats to the lower end of its daily range in the last hour.
placeholder
JPMorgan Raises S&P 500 Target; Can AI Sector Continue to Drive US Stocks?JPMorgan Chase has raised its year-end target for the S&P 500, noting that the core driver is not a simple recovery in sentiment, but rather upward earnings revisions for AI-related techn
Author  TradingKey
Yesterday 10: 31
JPMorgan Chase has raised its year-end target for the S&P 500, noting that the core driver is not a simple recovery in sentiment, but rather upward earnings revisions for AI-related techn
placeholder
Australian Dollar receives support after Trump extends ceasefire with IranAUD/USD pares its recent losses from the previous day, trading around 0.7160 during the Asian hours on Wednesday.
Author  FXStreet
Yesterday 01: 31
AUD/USD pares its recent losses from the previous day, trading around 0.7160 during the Asian hours on Wednesday.
placeholder
Tesla Q1 2026 Earnings Preview: 50,000-Unit Inventory Overhang, Energy Storage Halved, 5 Core Metrics Long-Term Investors Should Really WatchIntroductionTesla (TSLA) is scheduled to release its first-quarter 2026 earnings report after the U.S. market close on April 22. The Non-GAAP EPS consensus from Tesla's official compilation (comprisin
Author  TradingKey
Apr 21, Tue
IntroductionTesla (TSLA) is scheduled to release its first-quarter 2026 earnings report after the U.S. market close on April 22. The Non-GAAP EPS consensus from Tesla's official compilation (comprisin
goTop
quote