:
[SECURITY]■ STORY TIMELINE

BITWARDEN CLI NPM PACKAGE POISONED WITH CREDENTIAL STEALER

Attackers compromised the @bitwarden/cli package on npm, injecting malicious code designed to steal developer credentials. The malicious version was removed after discovery, but exposed a supply chain vulnerability affecting password manager users.

1 SOURCEFIRST SEEN APR 23, 07:21 PM► READ THE ARTICLE
Bleeping Computer+0m

The Bitwarden CLI was briefly compromised after attackers uploaded a malicious @bitwarden/cli package to npm containing…