惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园_首页
雷峰网
雷峰网
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
WordPress大学
WordPress大学
腾讯CDC
T
Tailwind CSS Blog
A
About on SuperTechFans
H
Hackread – Cybersecurity News, Data Breaches, AI and More
The GitHub Blog
The GitHub Blog
T
The Blog of Author Tim Ferriss
G
Google Developers Blog
The Cloudflare Blog
D
DataBreaches.Net
Recent Announcements
Recent Announcements
Engineering at Meta
Engineering at Meta
B
Blog
博客园 - 聂微东
阮一峰的网络日志
阮一峰的网络日志
月光博客
月光博客
博客园 - 司徒正美
MongoDB | Blog
MongoDB | Blog
Google DeepMind News
Google DeepMind News
Apple Machine Learning Research
Apple Machine Learning Research

Forbes - Innovation

Why Do Humans Have Fingerprints? Hint: It’s Not What You Think Booking.com Confirms Data Breach, Reservation PIN Codes Changed Why Major News Sites Are Blocking The Internet Archive’s Wayback Machine iPhone Fold Release Date: New Report Details Frustrating Apple News Comet Tracker: How To See Pan-STARRS And Three Planets On Wednesday NYT Mini Crossword Today: Tuesday, April 14 Hints And Answers Today’s NYT Strands Hints, Spangram, Answers: Tuesday, April 14 (It’s A Little Unclear) Today’s Wordle #1760 Hints And Answer For Tuesday, April 14 Most Of The Microplastics In Urban Air Come From Tires Today’s Wordle #1759 Hints And Answer For Monday, April 13 NYT Mini Crossword Today: Monday, April 13 Hints And Answers NYT Pips Today: Hints, Answers And Walkthrough For Monday, April 13 The YC Chief Who Codes 10,000 Lines A Day Has A Simple Secret Samsung Expands One UI 8.5 Beta To More Galaxy Owners Why You Should Stop Using Your iPhone If It’s On This List Chamath Says Firms That Treat AI As A Strategy Hand Rivals Their Edge 3 Unexpected Habits Of Secure Couples, By A Psychologist The First Lamp That Folds Your Clothes Samsung’s Disappointing Price Update For Galaxy Phone Buyers 3 Subtle Signs Someone Is Falling In Love With You, By A Psychologist Do Mantis Shrimp See More Colors Than Humans? A Biologist Explains NYT Connections Answers Explained For Monday, April 13 (#1,037) NYT Connections Hints Today: Monday, April 13 Clues And Answers (#1,037) LEGO Luigi & Mach 8 (72050) Review: 2026’s Best Set Yet? Marc Andreessen Says AI Productivity Will Trigger A Hiring Boom 3D Printing Is The Ultimate Hack To Reduce Household Spending Apple iPhone Fold: Striking Design Revealed In Leaked Photos Apple Smart Glasses: New Leak Reveals A Major Design Twist To Beat Meta Tested: The AI Coming To The Rivian R2 Quordle Hints Today: Monday, April 13 Clues And Answers
Bitwarden Confirms Compromise—Here Are The Facts
Davey Winder · 2026-04-24 · via Forbes - Innovation
The word 'password' is displayed in red against green binary code.

Password manager company Bitwarden confirms NPM package compromise.

getty

The advice has been clear from security experts for the longest time: use a password manager. And that advice still stands, despite the news that one of the leaders in the market, Bitwarden, has confirmed a serious security incident that led to a compromised product being released for a short period of time. If installed, the malicious Bitwarden CLI Node Package Manager product included a credential-stealing payload. Bitwarden is the latest in a line of npm package supply chain compromises, but for the vast majority of Bitwarden password manager users, the sky has not fallen, and there is no need for panic.

ForbesGoogle Android PIN Hackers Target 800 Apps During Attack SurgeBy Davey Winder

The Truth About The Bitwarden Attack

Despite the, perhaps inevitable, manic response on social media platforms to the news that Bitwarden had confirmed a security incident, the actual facts of the matter are that, while obviously very serious, this is not the end of the password manager, and the vast majority of users do not need to actually do anything in response. This is, in no way, downplaying the impact that any security incident has on the trust of its users when password managers are concerned. However,while this is not another phishing attack targeting password manager users, it is far worse than that, it is important not to get carried away and to focus on the facts.

Firstly, this incident affected only users of the Bitwarden CLI product, not the password manager app itself. This is the command-line interface, the terminal version of Bitwarden. Already, the number of users has dropped very dramatically from the estimated 10 million who use the main product. While I was unable to gather any official statistics, Bitwarden CLI npm package has around 250,000 downloads monthly, according to an OX Security analysis.

That’s still a considerable number, so let’s introduce fact number two: Bitwarden has confirmed in a statement that it had “identified and contained a malicious package that was briefly distributed through the npm delivery path for @bitwarden/cli@2026.4.0 between 5:57 PM and 7:30 PM (ET) on April 22, 2026, in connection with a broader Checkmarx supply chain incident.” To put that into further context, according to a moderator of the Bitwarden community forum, “it seems that only 334 Bitwarden users downloaded the malicious version of the CLI,” during the time it was available.

MORE FOR YOU

ForbesDangerous Fake Microsoft Windows Update Confirmed—Do Not DownloadBy Davey Winder

A Bitwarden spokesperson said: “The investigation found no evidence that end-user vault data was accessed or at risk, or that production data or production systems were compromised. Once the issue was detected, compromised access was revoked, the malicious npm release was deprecated, and remediation steps were initiated immediately. The issue affected the npm distribution mechanism for the CLI during that limited window, not the integrity of the legitimate Bitwarden CLI codebase or stored vault data.”

If you were not among the few hundred to have downloaded the package, then you can relax, your passwords are safe. If you did, however, then Bitwarden recommends you uninstall Bitwarden CLI 2026.4.0 via npm, clear the npm cache, disable npm install scripts during cleanup as a precaution, rotate any secrets that may have been exposed on the affected system or stored in environment variables including API tokens and SSH keys, and finally install Bitwarden CLI 2026.4.1