#4
SecurityWeek
general
April 24, 2026 at 08:07 UTC
Bitwarden NPM Package Hit in Supply Chain Attack
By Ionut Arghire
AI Summary
TeamPCP compromised the Bitwarden CLI NPM package (@bitwarden/[email protected]) in a supply chain attack, injecting malicious code into the 'bw1.js' file. The attack is part of a broader Checkmarx supply chain campaign targeting developer tools and password management infrastructure.
Relevance score: 85.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →