Bitwarden CLI npm package compromised to steal developer credentials
2026-04-23T19:23:36Z•8d9a8fba4bfea5f79d203ee3952bc2b68b1bc902ac608ea7dc8e3cbbbefa4ac3
CVE-2025-29635apple-iosbitwardenbluehammercheckmarxcredential-theftexfiltrationgopherwhisperkybermirainpmproxy-botnetransomwareself-spreading-malwaresupply-chaintoken-thefttrigonazero-day
What happened
Multiple active threats reported: a wave of supply‑chain attacks targeting developer tooling (malicious npm packages including a compromised @bitwarden/cli, and tampered Checkmarx KICS images/extensions) that steal developer credentials and auth tokens and can self‑propagate; ransomware campaigns (Trigona using a custom CLI exfiltration tool; Kyber variants experimenting with post‑quantum Kyber1024 encryption); a Mirai campaign exploiting CVE-2025-29635 in EoL D‑Link routers to build botnets; a CISA order to patch a Microsoft Defender privilege‑escalation flaw dubbed “BlueHammer” exploited asa
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 8d9a8fba4bfea5f79d203ee3952bc2b68b1bc902ac608ea7dc8e3cbbbefa4ac3
- Enrichment time
- 2026-04-23T19:23:36Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.