Malicious Bitwarden CLI briefly published on npm for 93 minutes on April 22, targeting developer credentials; Bitwarden says no vault data was accessed
On Apr. 22, 2026, a malicious build of Bitwarden’s command-line interface briefly appeared on npm under the official package name…





