Darnley's Cyber Café
Darnley's Cyber Café
Darnley's Cyber Café
Bitwarden CLI Hacked? The Supply Chain Attack That Targeted 250K Developers
21 minutes Posted Apr 29, 2026 at 8:00 am.
Intro
The 93-Minute Window: What Happened
The Supply Chain Vector: How They Got In
The Shai-Hulud Payload: What the Malware Did
The 'No Vault Data' Problem
Practical Defence: What You Can Do
Final Thoughts / Outro
0:00
21:31
Download MP3
Show notes
On April 22, 2026, the Bitwarden CLI, used in CI/CD pipelines at tens of thousands of organizations, was weaponized for exactly 93 minutes. In this episode, Darnley walks through the anatomy of the supply chain attack that compromised bitwarden cli version 2026.4.0: how the threat group exploited a compromised Checkmarx GitHub Action to inject credential-stealing malware into Bitwarden's npm publishing pipeline, what the worm actually stole, how it self-propagated by republishing victim...