惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
Visual Studio Blog
Engineering at Meta
Engineering at Meta
月光博客
月光博客
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
T
Tailwind CSS Blog
博客园 - Franky
The GitHub Blog
The GitHub Blog
大猫的无限游戏
大猫的无限游戏
The Cloudflare Blog
B
Blog RSS Feed
云风的 BLOG
云风的 BLOG
小众软件
小众软件
罗磊的独立博客
Microsoft Azure Blog
Microsoft Azure Blog
I
InfoQ
美团技术团队
H
Hackread – Cybersecurity News, Data Breaches, AI and More
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
V
V2EX
C
Check Point Blog
WordPress大学
WordPress大学
博客园 - 【当耐特】
博客园 - 司徒正美
D
Docker

Forbes - Consumer Tech

This Unhackable Quantum Navigation System Is The Size Of A Loaf Of Bread Apple At 50 — A Leadership Shift And An AR Future We Are Under-Investing In Robotics ... 90% Of Humanoid Robots Are Made In China Ditch The Apple White: Beats Expands Colorful Cable Line-Up With New 10-Foot Option Satechi’s New ChargeView 140W Desktop GaN Charger With Real-Time Display The Hasselblad In Your Pocket: Oppo’s Find X9 Ultra Challenges The Galaxy S26 Ultra There's No Such Thing As Brain Honey How AI Agents Could Rebuild Fashion’s Visual Production Layer QClaw Goes Global. The Agent Built Itself In 5 Days Apple’s Tim Cook Exit Hides A $4 Trillion Agentic AI Power Move EZQuest Reveals A New Line Of Pro Series USB-C Hubs For MacBook Neo Samsung Galaxy Z TriFold 2 Already In The Works, Report Claims Apple Revealed New Siri Release Date For iPhone, Latest Report Claims How Arcani’s HARK Is Designed For Modern Battlefield Acoustics The Newest Trend In Tech Embraces Femininity And Fun Samsung’s 75R95H Ushers In A New World Of LCD TVs New Apple iPhone Fold Design Pushes Smartphone Rivals To Go Wider And Taller iPhone 18 Pro Report: Four New Colors Leak As Apple Cancels Popular Shade Nothing’s Design-Led Strategy: Carl Pei Reveals The Tech Brand’s Philosophy iOS 26.5 Release Date: When To Expect Your iPhone Messaging Upgrade Google Pixel And Highsnobiety Build A Talent Pipeline For Fashion Android Circuit: Samsung Raises Galaxy Prices, Oppo Pad Mini Teased, Microsoft Closing Outlook App Apple Loop: iPhone Fold Launch Dates, iPad Air Upgrade, iPhone 18 Pro Specs Comcast $117.5 Million Breach Settlement — Are You Eligible? Amazfit Cheetah 2 Pro Takes Aim At The Garmin Audience Disney’s Launches ‘Infinity Vision’ Certification For Premium Theaters SoundPeats Reveals New Air6 HS Semi-Open Wireless Earbuds Amazon’s $11.57 Billion Leap Into Space: A Challenge To Starlink Meta Quest 3 Hit With $100 Price Increase Backblaze Stops Backing Up Dropbox And Others—Calls It An Improvement
Bitwarden Confirms Compromise—Here Are The Facts
Davey Winder · 2026-04-24 · via Forbes - Consumer Tech
The word 'password' is displayed in red against green binary code.

Password manager company Bitwarden confirms NPM package compromise.

getty

The advice has been clear from security experts for the longest time: use a password manager. And that advice still stands, despite the news that one of the leaders in the market, Bitwarden, has confirmed a serious security incident that led to a compromised product being released for a short period of time. If installed, the malicious Bitwarden CLI Node Package Manager product included a credential-stealing payload. Bitwarden is the latest in a line of npm package supply chain compromises, but for the vast majority of Bitwarden password manager users, the sky has not fallen, and there is no need for panic.

ForbesGoogle Android PIN Hackers Target 800 Apps During Attack SurgeBy Davey Winder

The Truth About The Bitwarden Attack

Despite the, perhaps inevitable, manic response on social media platforms to the news that Bitwarden had confirmed a security incident, the actual facts of the matter are that, while obviously very serious, this is not the end of the password manager, and the vast majority of users do not need to actually do anything in response. This is, in no way, downplaying the impact that any security incident has on the trust of its users when password managers are concerned. However,while this is not another phishing attack targeting password manager users, it is far worse than that, it is important not to get carried away and to focus on the facts.

Firstly, this incident affected only users of the Bitwarden CLI product, not the password manager app itself. This is the command-line interface, the terminal version of Bitwarden. Already, the number of users has dropped very dramatically from the estimated 10 million who use the main product. While I was unable to gather any official statistics, Bitwarden CLI npm package has around 250,000 downloads monthly, according to an OX Security analysis.

That’s still a considerable number, so let’s introduce fact number two: Bitwarden has confirmed in a statement that it had “identified and contained a malicious package that was briefly distributed through the npm delivery path for @bitwarden/cli@2026.4.0 between 5:57 PM and 7:30 PM (ET) on April 22, 2026, in connection with a broader Checkmarx supply chain incident.” To put that into further context, according to a moderator of the Bitwarden community forum, “it seems that only 334 Bitwarden users downloaded the malicious version of the CLI,” during the time it was available.

MORE FOR YOU

ForbesDangerous Fake Microsoft Windows Update Confirmed—Do Not DownloadBy Davey Winder

A Bitwarden spokesperson said: “The investigation found no evidence that end-user vault data was accessed or at risk, or that production data or production systems were compromised. Once the issue was detected, compromised access was revoked, the malicious npm release was deprecated, and remediation steps were initiated immediately. The issue affected the npm distribution mechanism for the CLI during that limited window, not the integrity of the legitimate Bitwarden CLI codebase or stored vault data.”

If you were not among the few hundred to have downloaded the package, then you can relax, your passwords are safe. If you did, however, then Bitwarden recommends you uninstall Bitwarden CLI 2026.4.0 via npm, clear the npm cache, disable npm install scripts during cleanup as a precaution, rotate any secrets that may have been exposed on the affected system or stored in environment variables including API tokens and SSH keys, and finally install Bitwarden CLI 2026.4.1