Bitwarden CLI Supply Chain Attack Exposes Crypto Wallet Keys

Attackers hijacked Bitwarden’s CLI version 2026.4.0 and published a malicious npm package that steals crypto wallet data and developer credentials. Socket discovered the breach on April 23 and linked it to the TeamPCP supply chain campaign. Affected workflows may have exposed GitHub and npm tokens, SSH keys, cloud credentials, and exchange API credentials used in automated crypto deployments.

This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin