Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› Bitwarden CLI npm Compromise 2026: How the Checkmarx…
Breach analysis Incident: 23 Apr 2026

Bitwarden CLI npm Compromise 2026: How the Checkmarx Campaign Hijacked a Password Manager’s Release Path to Steal Developer Tokens

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 8 October 2026 9 min read
On this page

On the evening of 22 April 2026 a malicious version of Bitwarden's command-line client, @bitwarden/cli 2026.4.0, was published to npm and stayed available for about 90 minutes. Bitwarden says the package went out through its npm delivery path between 5:57 PM and 7:30 PM Eastern Time and links the incident to the wider Checkmarx supply chain campaign. Socket says the attackers appear to have abused a GitHub Action in Bitwarden's CI/CD pipeline. The package ran a credential stealer at install time that took GitHub and npm tokens, SSH keys, cloud secrets, CI secrets and AI tool configuration, and could use stolen tokens to spread further. Bitwarden says it found no evidence that user vault data or its production systems were affected, and that only people who installed the CLI from npm in that window are at risk. The malicious release was deprecated, tracked as CVE-2026-42994 and replaced by 2026.4.1.

Key takeaways

  • Malicious @bitwarden/cli 2026.4.0 was distributed on npm between 5:57 PM and 7:30 PM ET on 22 April 2026, according to Bitwarden, and the company disclosed it the next day.
  • Bitwarden ties the incident to the Checkmarx supply chain compromise, and Socket says a compromised GitHub Action in Bitwarden's CI/CD pipeline appears to have been used. The exact credential path has not been published.
  • JFrog found the package layered malware over an older legitimate build. The payload took GitHub and npm tokens, SSH keys, AWS, GCP and Azure secrets, GitHub Actions secrets and AI coding tool configuration.
  • Bitwarden says there is no evidence that vault data or production systems were accessed. The risk falls on developers and pipelines that installed the CLI from npm in the window.
  • The identity lesson: a password manager's release pipeline is itself a set of machine identities, and a poisoned tool inside that pipeline can borrow them to ship malware.

At a glance

OrganisationBitwarden (password manager; @bitwarden/cli npm package) and developers and pipelines that installed version 2026.4.0
WhenDistributed 5:57 PM to 7:30 PM ET on 22 April 2026; disclosed 23 April 2026
AttackerLinked to the TeamPCP and Checkmarx campaign by JFrog and Socket; Socket says the attribution is complicated
Entry pointBitwarden's npm delivery path, reportedly through a compromised GitHub Action in its CI/CD pipeline
Identities abusedBitwarden's npm publishing path and CI credentials; then victims' GitHub and npm tokens, SSH keys, cloud secrets and CI secrets
ImpactCredential theft from systems that installed 2026.4.0; no evidence of vault data or production compromise, according to Bitwarden
CategoryNHI. Incident class: confirmed NHI breach (release pipeline credentials used to publish a credential-stealing package)

What happened

The Bitwarden CLI lets developers and scripts read secrets from a Bitwarden vault, so it is often installed on developer machines and in CI pipelines. On 23 April 2026 JFrog reported "a hijacked npm package published as @bitwarden/cli version 2026.4.0". A Bitwarden representative confirmed on GitHub: "We verified that a malicious version of CLI was published to NPM as 2026.4.0." In its formal statement Bitwarden said its security team "identified and contained a malicious package that was briefly distributed" through the npm delivery path between 5:57 PM and 7:30 PM ET on 22 April. It tied the incident to the broader Checkmarx supply chain incident, which hit Checkmarx's Docker images, extensions and a GitHub Action the same day.

JFrog found that the package's preinstall script and the bw command both pointed to a loader, bw_setup.js. The loader downloaded the Bun runtime if needed and ran an obfuscated second stage. The bundled application still carried 2026.3.0 metadata, which led JFrog to conclude that the malicious layer was added on top of an older legitimate release rather than built through Bitwarden's normal pipeline. The stealer collected GitHub tokens, including the output of gh auth token, npm tokens, SSH keys, .env files, shell history, AWS, GCP and Azure secrets, GitHub Actions secrets and configuration for AI coding tools such as Claude and Kiro. Results were encrypted and sent to the same attacker endpoint used in the Checkmarx attack. If that failed, the stealer created a repository in the victim's own GitHub account. JFrog's verdict: "This is not passive credential theft."

The payload went further. With a valid GitHub token it listed writable repositories, committed a workflow to dump Actions secrets, then deleted the branch and run. OX Security, cited by BleepingComputer, says it could also use stolen npm tokens to inject packages the victim could publish, and that its exfiltration repositories carried the description "Shai-Hulud: The Third Coming". GitGuardian found it probing for six AI coding assistants and appending text to shell start-up files. Socket noted overlaps with the Checkmarx payload, including the same endpoint and obfuscation, but called attribution complicated because of the different branding. Bitwarden said: "The investigation found no evidence that end user vault data was accessed or at risk." It revoked the compromised access and deprecated the release. Socket said the Chrome extension, MCP server and other distributions were not affected.

Timeline

DateEvent
19 March 2026Checkmarx's GitHub repositories are accessed through the Trivy supply chain attack, according to Checkmarx.
22 April 2026The second Checkmarx wave publishes malicious KICS images, extensions and a GitHub Action.
22 April 2026Malicious @bitwarden/cli 2026.4.0 is distributed on npm from 5:57 PM to 7:30 PM ET.
23 April 2026JFrog, Socket and GitGuardian publish analyses; Bitwarden confirms the malicious release and publishes its statement.

How it happened: the identity attack path

  1. A poisoned tool in the pipeline. Bitwarden links the incident to the Checkmarx compromise, and Socket says a compromised GitHub Action in Bitwarden's CI/CD pipeline appears to have been abused.
  2. The release path borrowed. Code running inside that pipeline could reach the credentials used to publish to npm, and a malicious 2026.4.0 was released under Bitwarden's name.
  3. Install-time execution. The preinstall hook ran the loader on every install, before anyone used the CLI.
  4. Developer and CI identities harvested. The stealer took GitHub, npm, cloud and SSH credentials and CI secrets from each machine that installed it.
  5. Stolen tokens turned into spread. Valid GitHub and npm tokens were used to plant secret-dumping workflows and, according to OX Security, to infect packages the victim could publish.

Impact

  • Confirmed: a malicious @bitwarden/cli 2026.4.0 distributed through npm for about 90 minutes, according to Bitwarden.
  • Not affected: end user vault data, Bitwarden production data and systems, and the legitimate CLI codebase, according to Bitwarden's investigation.
  • Potential: theft of GitHub, npm, cloud and SSH credentials and CI secrets from every system that installed the package in the window. No install count has been published.
  • Wider: stolen npm and GitHub tokens could seed further package compromises, the pattern seen across the TeamPCP campaign.

What this means for NHI governance

The Bitwarden incident is a reminder that a password manager's users trust two things, its encryption and its release pipeline. Bitwarden reports the first held. The second runs on non-human identities, including CI tokens, GitHub Action permissions and npm publishing rights. A third-party action running in the same pipeline can reach those identities. When the Checkmarx tools were poisoned, any pipeline that ran them with publishing credentials in scope was exposed.

The fixes are about scope and separation. Publishing jobs should hold the only credential that can publish, run no third-party scanners or actions, and use short-lived OIDC trusted publishing rather than stored tokens. Actions should be pinned by commit SHA so a moved tag cannot change what runs. See our CI/CD Pipeline Identity Security Guide and Secrets Management Guide.

The payload's interest in AI coding tool configuration and MCP files also matters. Those files increasingly hold tokens for code hosts, clouds and model providers, and they belong in the same rotation scope as .npmrc and SSH keys. See our AI Coding Agents Security Guide.

Recommendations

  • Remove 2026.4.0 and rotate. Uninstall the release, clear the npm cache, install 2026.4.1 and rotate every token and secret on affected machines and runners, as Bitwarden advises. See our Leaked Credential Response Playbook.
  • Isolate publishing jobs. Run release steps in a separate job with no third-party actions or scanners, and give only that job the publishing credential. See our CI/CD Pipeline Identity Security Guide.
  • Use trusted publishing. Replace stored npm tokens with OIDC trusted publishing tied to one workflow, so there is no long-lived token to steal.
  • Pin third-party Actions by SHA. Do not reference security tools by mutable tags in pipelines that hold secrets.
  • Disable install scripts where you can. Use ignore-scripts for CI installs that do not need them, which would have stopped this preinstall loader.
  • Review GitHub for planted workflows. Look for unexpected branches, deleted workflow runs and new public repositories in accounts that installed the package. See our Secrets Management Guide.

Frequently asked questions

Was my Bitwarden vault compromised?

Bitwarden says its investigation found no evidence that end user vault data was accessed or at risk, and no evidence that production data or systems were compromised. Only people who installed the CLI from npm between 5:57 PM and 7:30 PM ET on 22 April 2026 are affected.

How was the Bitwarden CLI compromised?

Bitwarden links the incident to the Checkmarx supply chain compromise. Socket says the attackers appear to have abused a GitHub Action in Bitwarden's CI/CD pipeline to publish a malicious 2026.4.0 to npm. Bitwarden has not published the exact credential path.

What did the malicious Bitwarden CLI steal?

According to JFrog and Socket, it took GitHub and npm tokens, SSH keys, .env files, shell history, AWS, GCP and Azure secrets, GitHub Actions secrets and AI coding tool and MCP configuration, then encrypted and exfiltrated them.

Checkmarx KICS supply chain attack 2026 · Trivy supply chain attack 2026 · Shai-Hulud npm Worm 2025 · CI/CD Pipeline Identity Security Guide · Leaked Credential Response Playbook

How NHI Mgmt Group can help

Release pipelines hold the credentials that decide what your users install. We help teams separate and scope those credentials, move to short-lived publishing and plan the rotation that follows a poisoned dependency. See our NHI and AI agent security training.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 8 October 2026.
Based on the public sources listed under References. Details may change as investigations continue.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org