Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Collapse
Brand Logo
UDS UDS: $1.5718
24h: -1.60%
Trade UDS
Gate.io
Gate.io
UDS / USDT
KuCoin
KuCoin
UDS / USDT
MEXC
MEXC
UDS / USDT
BingX
BingX
UDS / USDT
BitMart
BitMart
UDS / USDT
LBank
LBank
UDS / USDT
XT.COM
XT.COM
UDS / USDT
Uniswap v3
Uniswap v3
UDS / USDT
Biconomy.com
Biconomy.com
UDS / USDT
WEEX
WEEX
UDS / USDT
PancakeSwap v3
PancakeSwap v3
UDS / USDT
Pionex
Pionex
UDS / USDT
COINSTORE
COINSTORE
UDS / USDT
Sushiswap v3
Sushiswap v3
UDS / USDT
Picol
Picol
UDS / USDT

Earn up to 50 UDS per post

Post in Forum to earn rewards!

Learn more
UDS Right

Spin your Wheel of Fortune!

Earn or purchase spins to test your luck. Spin the Wheel of Fortune and win amazing prizes!

Spin now
Wheel of Fortune
selector
wheel
Spin

Paired Staking

Stake $UDS
APR icon Earn up to 50% APR
NFT icon Boost earnings with NFTs
Earn icon Play, HODL & earn more
Stake $UDS
Stake $UDS
UDS Left

Buy UDS!

Buy UDS with popular exchanges! Make purchases and claim rewards!

Buy UDS
UDS Right

INFLUENCER LEVEL

Based on the number of subscribers

MULTIPLIER

up to 10k

x1.1

10-25k

x1.25

25-100k

x1.5

100k-250k

x2

250k-1m

x3

1m+

x5

Post links to Undeads Forum messages or Undeads products to receive additional rewards

Post limits and staking coefficients applied similar to Forum posts

Discord, Telegram, Twiter

Post in Forum to earn rewards!

UDS Rewards
  1. Home
  2. Hero Portfolio
  3. Bitwarden CLI Hijacked in Supply Chain Attack — Crypto Wallets and Developer Credentials at Risk

Bitwarden CLI Hijacked in Supply Chain Attack — Crypto Wallets and Developer Credentials at Risk

Scheduled Pinned Locked Moved Hero Portfolio
2 Posts 2 Posters 17 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
This topic has been deleted. Only users with topic management privileges can see it.
  • tradelikeproT Offline
    tradelikeproT Offline
    tradelikepro
    wrote last edited by
    #1

    1802a6b4-74bb-495f-913a-ac55101ece97-image.png
    Attackers have compromised Bitwarden's CLI version 2026.4.0 through a hijacked GitHub Action, injecting a malicious npm package designed to steal sensitive data during installation. Security firm Socket discovered the breach on April 23, linking it to the ongoing TeamPCP supply chain campaign. The rogue package has since been pulled, but any developer or team that installed the compromised version during that window may already be affected.

    The malicious payload, embedded in a file called bw1.js, targeted a wide range of high-value credentials including GitHub and npm tokens, SSH keys, environment variables, shell history, and cloud credentials. TeamPCP's broader campaign is separately confirmed to go after crypto wallet data, including files associated with MetaMask, Phantom, and Solana wallets. Stolen data was exfiltrated to attacker-controlled domains and committed back to GitHub repositories as a persistence mechanism.

    The breach is particularly serious for crypto teams, as many use the Bitwarden CLI in automated CI/CD pipelines for secrets injection and deployments. Any workflows that ran version 2026.4.0 may have exposed wallet keys and exchange API credentials. Security researcher Adnan Khan noted this is the first known compromise of a package using npm's trusted publishing mechanism — a system specifically designed to eliminate long-lived tokens.

    1 Reply Last reply
    0
    • madtraderM Offline
      madtraderM Offline
      madtrader
      wrote last edited by
      #2

      "rotate every exposed secret without delay" printed this out and taped it above my monitor. it has been there since the last supply chain incident. it will stay there.

      1 Reply Last reply
      0


      • Login or register to search.
      Powered by NodeBB Contributors
      • First post
        Last post
      0
      • Categories
      • Recent
      • Tags
      • Popular
      • World
      • Users
      • Groups