Bitwarden CLI npm Package Compromised in Sophisticated GitHub Actions Supply Chain Attack
Security researchers at Socket have confirmed that the official Bitwarden CLI npm package (version 2026.4.0) was tampered with via a compromised GitHub Actions workflow, injecting credential-stealing malware as part of the ongoing Checkmarx supply chain campaign targeting enterprise CI/CD pipelines.
Itagora tiene in archivio titolo e sommario per la ricerca interna. Il testo completo resta sulla fonte. Il link in uscita non invia referrer.