Checkmarx supply chain attack impacts Bitwarden npm distribution path

2026-04-24T14:51:49Z0e5cdced46cbb76b94f64bce614261bb554fc65614116ae849f477f840ede482
aspnet-corebitwardenbotnetcheckmarxchina-linkedconsumer-iotd-linkdata-breachgithub-actionsgogra-malware','harvester','ddos','mastodon','blueskyioskevknown-exploited-vulnerabilitymalicious-packagemicrosoft-defendermicrosoft-graph-apimirainotification-servicesnpmout-of-band-patchproxy-networkramp-leakransomware-marketplaceritualssupply-chain

What happened

Multiple high-impact incidents and active exploitation observed: a Checkmarx supply-chain campaign compromised a GitHub Action and injected malicious code (bw1.js) into @bitwarden/cli 2026.4.0; CISA added Microsoft Defender flaw CVE-2026-33825 to its KEV catalog; Mirai botnets are actively exploiting CVE-2025-29635 in legacy D-Link routers; Microsoft released out-of-band fixes for a critical ASP.NET Core privilege-escalation (CVE-2026-40372, CVSS 9.1). Other notable items include an iOS Notification Services flaw (CVE-2026-28950) patched by Apple, new GoGra Linux malware abusing Microsoft Gl​​

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
0e5cdced46cbb76b94f64bce614261bb554fc65614116ae849f477f840ede482
Enrichment time
2026-04-24T14:51:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.