Bitwarden CLI npm package compromised to steal developer credentials
BleepingComputer [Unofficial]
April 23, 2026
The Bitwarden CLI was briefly compromised after attackers uploaded a malicious @bitwarden/cli package to npm containing a credential-stealing payload capable of spreading to other projects. [...]
Discussion in the ATmosphere