<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Bitwarden CLI遭供应链攻击，逾千万用户面临凭据泄露风险]]></title><description><![CDATA[<p dir="auto">Bitwarden CLI遭供应链攻击，逾千万用户面临凭据泄露风险<br />
安全研究机构Socket披露，Bitwarden CLI 2026.4.0版本遭到入侵，攻击者利用Bitwarden CI/CD流水线中的一个GitHub Action漏洞植入恶意代码，此次事件是持续进行中的Checkmarx供应链攻击活动的一部分。Bitwarden拥有逾1000万用户及5万余家企业客户，是全球排名前三的密码管理工具之一。 ￼<br />
恶意载荷隐藏于bw1.js文件中，可窃取GitHub Token、AWS/Azure/GCP云凭据、npm配置、SSH密钥及Claude/MCP配置文件等敏感信息，并通过加密提交的方式将数据外泄至攻击者控制的公开GitHub仓库。此次攻击还具备Shell持久化能力，会向~/.bashrc和~/.zshrc注入恶意代码。值得注意的是，恶意程序内置俄语区域设置检测，若系统语言为俄语则静默退出。目前仅npm版本的CLI受到影响，Chrome扩展及其他官方发行版尚未波及。 ￼<br />
Socket建议受影响用户立即卸载该版本、轮换所有相关凭据，并排查GitHub是否存在异常仓库创建或工作流注入。</p>
<p dir="auto"><a href="https://socket.dev/blog/bitwarden-cli-compromised" target="_blank" rel="noopener noreferrer nofollow ugc">Socket</a></p>
<p dir="auto"><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">



<a href="https://socket.dev/blog/bitwarden-cli-compromised" title="Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain ...">
<img src="https://cdn.sanity.io/images/cgdhsj6q/production/65ef8dc5e66260e20fdf13cead82ebd41b705ee6-1018x666.png?w=1000&q=95&fit=max&auto=format" class="card-img-top not-responsive" style="max-height: 15rem;" alt="Link Preview Image" onerror="this.parentElement.remove()" />
</a>



<div class="card-body">
<h5 class="card-title">
<a class="text-decoration-none" href="https://socket.dev/blog/bitwarden-cli-compromised">
Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain ...
</a>
</h5>
<p class="card-text line-clamp-3">Bitwarden CLI 2026.4.0 was compromised in the Checkmarx supply chain campaign after attackers abused a GitHub Action in Bitwarden’s CI/CD pipeline.</p>
</div>
<a href="https://socket.dev/blog/bitwarden-cli-compromised" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://socket.dev/favicon-32x32.png" alt="favicon" class="not-responsive overflow-hiddden" style="max-width: 21px; max-height: 21px;" onerror="this.remove()"/>









<p class="d-inline-block text-truncate mb-0">Socket <span class="text-secondary">(socket.dev)</span></p>
</a>
</div></p>
]]></description><link>https://welinux.com//topic/31/bitwarden-cli遭供应链攻击-逾千万用户面临凭据泄露风险</link><generator>RSS for Node</generator><lastBuildDate>Mon, 18 May 2026 17:18:12 GMT</lastBuildDate><atom:link href="https://welinux.com//topic/31.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 23 Apr 2026 19:56:28 GMT</pubDate><ttl>60</ttl></channel></rss>