CoinWorld News, the Bitwarden security team reminds users that due to the Checkmarx supply chain attack, the /cli version 2026.4.0 was briefly released with malicious packages on npm on April 22nd, affecting only users who installed between 5:57 pm and 7:30 pm Eastern Time. The official confirmation states that vault data was not leaked, and production systems were not compromised. It is recommended that affected users immediately uninstall 2026.4.0, clear npm cache, rotate sensitive credentials such as API tokens and SSH keys, check for abnormal activity on GitHub and CI, and upgrade to 2026.4.1.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin