Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign
TL;DR Highlight
Bitwarden CLI npm package delivers malware via GitHub Actions, stealing user credentials.
Who Should Read
Developers and DevOps engineers installing npm packages in CI/CD pipelines or using the Bitwarden CLI, especially teams automating dependency installation in GitHub Actions workflows.
Core Mechanics
- The affected version, @bitwarden/cli 2026.4.0, had malicious code inserted into the bw1.js file. Attackers compromised Bitwarden’s GitHub Actions CI/CD pipeline to inject the payload into build artifacts.
- This incident is part of the Checkmarx supply chain campaign—a series of attacks targeting the npm ecosystem—and shares the same C2 endpoint (audit.checkmarx[.]cx/v1/telemetry) and payload structure as previously analyzed mcpAddon.js.
- The malicious payload scrapes the memory of GitHub Actions Runners to steal GitHub tokens, AWS credentials from ~/.aws/ files and environment variables, Azure/GCP/npm tokens from azd·gcloud·~/.npmrc, and even Claude/MCP configuration files.
- Stolen npm tokens are used to find other npm packages with write access, injecting malicious code into the preinstall hook for redistribution. Public repositories on GitHub are also created with Dune novel-themed names ({word}-{word}-{3-digit number}) to commit encrypted results.
- A Russian locale killswitch causes the malware to silently exit if the system locale starts with 'ru', checking Intl.DateTimeFormat().resolvedOptions().locale and the LC_ALL, LC_MESSAGES, LANGUAGE, and LANG environment variables.
- Because the malicious payload executes during the npm install preinstall hook, existing security practices of scanning code after installation are ineffective. CI/CD environments with automated installation are particularly vulnerable due to short exposure windows.
- Impact was limited as the Bitwarden CLI does not auto-update, with approximately 334 downloads affected. Browser extensions, MCP servers, and other official distributions remain unaffected.
- The payload injects itself into ~/.bashrc and ~/.zshrc to maintain persistence after shell restarts, and incorporates ideological branding from Dune novels ('Shai-Hulud', 'Butlerian Jihad')—a departure from previous Checkmarx campaigns.
Evidence
- "Practical advice was shared that setting a minimum release age for npm package installations can defend against such attacks. Setting min-release-age=7 (days) in .npmrc (npm 11.10+) could have prevented this package (~19 hours to discovery/deprecation) and previous quickly-removed cases like axios and ua-parser-js."
How to Apply
- If using npm/pnpm/bun/uv, add a minimum release age to your package manager configuration. Set min-release-age=7 in ~/.npmrc, minimum-release-age=10080 (minutes) in pnpm rc, and minimumReleaseAge = 604800 (seconds) in ~/.bunfig.toml to prevent newly deployed malicious packages from automatically installing.
- In CI/CD pipelines, pin package versions in package.json without the ^ range and commit the lockfile. For critical tools like Bitwarden CLI, always pin versions.
- If currently using Bitwarden CLI, check CI logs for use of the affected version (2026.4.0) and immediately rotate any secrets (GitHub tokens, AWS/GCP/Azure credentials, npm tokens, SSH keys) potentially exposed in that workflow. Refer to the Bitwarden community for the timeframe of compromise.
- If using GitHub Actions, pin third-party Action versions to SHA hashes and remove unnecessary secret access permissions to minimize the blast radius of a compromise.
Code Example
# ~/.npmrc (npm 11.10+ required)
min-release-age=7 # Unit: days
# ~/Library/Preferences/pnpm/rc
minimum-release-age=10080 # Unit: minutes
# ~/.bunfig.toml
[install]
minimumReleaseAge = 604800 # Unit: seconds
# ~/.config/uv/uv.toml (Python uv package manager)
exclude-newer = "7 days"Terminology
Related Papers
Show HN: adamsreview – better multi-agent PR reviews for Claude Code
Claude Code에서 최대 7개의 병렬 서브 에이전트가 각각 다른 관점으로 PR을 리뷰하고, 자동 수정까지 해주는 오픈소스 플러그인이다. 기존 /review나 CodeRabbit보다 실제 버그를 더 많이 잡는다고 주장하지만 커뮤니티에서는 복잡도와 실효성에 대한 회의론도 나왔다.
How Fast Does Claude, Acting as a User Space IP Stack, Respond to Pings?
Claude Code에게 IP 패킷을 직접 파싱하고 ICMP echo reply를 구성하도록 시켜서 실제로 ping에 응답하게 만든 실험으로, 'Markdown이 곧 코드이고 LLM이 프로세서'라는 아이디어를 네트워크 스택 수준까지 밀어붙인 재미있는 사례다.
Show HN: Git for AI Agents
AI 코딩 에이전트(Claude Code 등)가 수행한 모든 툴 호출을 자동으로 추적하고, 어떤 프롬프트가 어느 코드 줄을 작성했는지 blame까지 가능한 버전 관리 도구다.
Principles for agent-native CLIs
AI 에이전트가 CLI 도구를 더 잘 사용할 수 있도록 설계하는 원칙들을 정리한 글로, 에이전트가 CLI를 도구로 활용하는 빈도가 높아지면서 이 설계 방식이 실용적으로 중요해지고 있다.
Agent-harness-kit scaffolding for multi-agent workflows (MCP, provider-agnostic)
여러 AI 에이전트가 서로 역할을 나눠 협업할 수 있도록 조율하는 scaffolding 도구로, Vite처럼 설정 없이 빠르게 멀티 에이전트 파이프라인을 구성할 수 있다.
Show HN: Tilde.run – Agent sandbox with a transactional, versioned filesystem
AI 에이전트가 실제 프로덕션 데이터를 건드려도 롤백할 수 있는 격리된 샌드박스 환경을 제공하는 도구로, GitHub/S3/Google Drive를 하나의 버전 관리 파일시스템으로 묶어준다.
Related Resources
- Original Article: Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign
- Bitwarden Official Statement
- rbw: A Bitwarden CLI alternative written in Rust
- DepsGuard: Package Manager Security Configuration Helper
- Cooldowns.dev: Package Release Cooldown Setting Tool
- The Install Was the Attack (AgentSH Blog)