9
you are viewing a single comment's thread
view the rest of the comments
[-] nocturne@slrpnk.net 5 points 1 month ago
[-] eager_eagle@lemmy.world 4 points 1 month ago* (last edited 1 month ago)

Yesterday, for about 1h30min (starting at 5:57pm ET / 21:57 UTC) anyone installing the latest version of the command line interface of bitwarden was installing malware.

The malware steals GitHub/npm tokens, .ssh, .env, shell history, GitHub Actions and cloud secrets, then exfiltrates the data to private domains and as GitHub commits and doesn't seem to be targeting Bitwarden specifically, or user vaults.

There's no evidence that end user vault data was accessed or at risk, or that production data or production systems were compromised, according to their official statement.

It seems there were 334 bitwarden CLI downloads in this time period, some or many of which might have been from bots, so this is a higher bound to the number of affected users.

[-] nocturne@slrpnk.net 2 points 1 month ago

So if you use the phone app, or browser extension you are okay?

this post was submitted on 23 Apr 2026
9 points (90.9% liked)

Bitwarden

1183 readers
1 users here now

Discuss the Paswordmanager Bitwarden.

founded 2 years ago
MODERATORS