<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Bitwarden&#x27;s CLI NPM package was hijacked and used to spread credential stealer malware.]]></title><description><![CDATA[<p>Bitwarden's CLI NPM package was hijacked and used to spread credential stealer malware. This is related to the previous Checkmarx compromise.</p><p>We'll be updating this thread as always with new information. Come join the effort!</p><p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">



<a href="https://discourse.ifin.network/t/teampcp-campaign-spreads-to-npm-via-a-hijacked-bitwarden-cli/305" title="TeamPCP Campaign Spreads to npm via a Hijacked Bitwarden CLI">
<img src="https://discourse.ifin.network/uploads/default/original/1X/6824644240c7d8465c68fc044fe67b4020d74a7d.png" class="card-img-top not-responsive" style="max-height: 15rem;" alt="Link Preview Image" />
</a>



<div class="card-body">
<h5 class="card-title">
<a href="https://discourse.ifin.network/t/teampcp-campaign-spreads-to-npm-via-a-hijacked-bitwarden-cli/305">
TeamPCP Campaign Spreads to npm via a Hijacked Bitwarden CLI
</a>
</h5>
<p class="card-text line-clamp-3">From: 


Kill Chain: 

The root package.json advertises @bitwarden/cli version 2026.4.0, while the embedded application metadata in build/bw.js still references 2026.3.0. That mismatch strongly suggests the malicious pac&hellip;</p>
</div>
<a href="https://discourse.ifin.network/t/teampcp-campaign-spreads-to-npm-via-a-hijacked-bitwarden-cli/305" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://discourse.ifin.network/uploads/default/optimized/1X/ea367a05f4a0d090bf61d140dc84f744c9ab9bf0_2_32x32.png" alt="favicon" class="not-responsive overflow-hiddden" style="max-width: 21px; max-height: 21px;" />





<p class="d-inline-block text-truncate mb-0">IFIN <span class="text-secondary">(discourse.ifin.network)</span></p>
</a>
</div></p>]]></description><link>https://board.circlewithadot.net/topic/2aaca3c6-a2b2-45aa-866c-7592e2bf091c/bitwarden-s-cli-npm-package-was-hijacked-and-used-to-spread-credential-stealer-malware.</link><generator>RSS for Node</generator><lastBuildDate>Thu, 30 Apr 2026 14:26:19 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/2aaca3c6-a2b2-45aa-866c-7592e2bf091c.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 23 Apr 2026 15:08:31 GMT</pubDate><ttl>60</ttl></channel></rss>