Threat reportSupply ChainTL-2026-0425

Bitwarden CLI Hijacked in npm Supply Chain Attack Linked to TeamPCP & Checkmarx Breach

criticalMONITORING

Bitwarden CLI Hijacked in npm Supply Chain Attack Linked to (TL-2026-0425), also tracked as Operation TeamPCP-Vault, is a critical-severity supply-chain compromise scored CVSS 9.6, first published 2026-04-27. It is attributed to TeamPCP with high confidence, affects Bitwarden @bitwarden/cli (npm), maps to 25 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 20 indicators of compromise.

CVSS
9.6/10Critical
CVEs
0None referenced
Techniques
25MITRE ATT&CK
Actors
1TeamPCP
Detection rules
9SPL · KQL · Sigma
IOCs
20Indicators of compromise

Key facts for TL-2026-0425

Threat ID
TL-2026-0425
Also known as
Operation TeamPCP-Vault, Bitwarden-CLI-Hijack-2026, PCP-Cascade
Severity
CRITICAL
CVSS
9.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H)
Status
MONITORING
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution
TeamPCP
Attribution confidence
HIGH
Motivation
FINANCIAL
Target sectors
technology, financial, healthcare, government, managed-service-providers, saas, devops, open-source-maintainers
Target regions
North America, Europe, Asia-Pacific, Global
Detection rules
9
Indicators of compromise
20

Malware and tooling in Bitwarden CLI Hijacked in npm Supply Chain Attack Linked to

Malware and tooling: PCP-VaultStealer, Cloudflare Workers fronted PCP-Relay, TeamPCP Packer v3 (control-flow flattened JS with AES-GCM key wrapping)

How Bitwarden CLI Hijacked in npm Supply Chain Attack Linked to works

TeamPCP threat actors published a trojanized version of the @bitwarden/cli package to the npm registry on 2026-04-22, exposing CI/CD pipelines and developer workstations to credential vault exfiltration during a 90-minute window before takedown. The compromise leveraged maintainer credentials harvested from the prior Checkmarx breach and represents a cascading supply chain attack against credential management tooling.

On April 22, 2026, between approximately 14:32 UTC and 16:02 UTC, a malicious version of the @bitwarden/cli npm package (advertised as v2026.4.7) was published to the npm public registry by an account belonging to a legitimate Bitwarden release engineer whose credentials had been stolen during the March-April 2026 Checkmarx breach. The hijacked package was downloaded approximately 11,400 times across automated CI/CD pipelines, developer workstations, and container build images before npm Trust & Safety removed it following an internal anomaly alert and Bitwarden security team notification.

The trojanized package shipped with a benign-looking postinstall.js hook that decoded a Base64-encoded second-stage JavaScript payload at install time. The payload performed three primary actions: (1) it walked the local filesystem looking for Bitwarden vault export files (.json, .csv) under common paths; (2) it harvested high-value secret material from environment variables, .env files, ~/.aws/credentials, ~/.ssh/id_rsa, ~/.config/gh/hosts.yml, ~/.docker/config.json, and the GITHUB_TOKEN/NPM_TOKEN/CIRCLE_TOKEN family of CI variables; and (3) it called bw export with the BW_SESSION variable when present to extract live unlocked vaults. Stolen data was AES-256-GCM encrypted with an embedded public key, then exfiltrated over HTTPS to a Cloudflare Worker proxy (telemetry-collector[.]bitwarden-cli-stats[.]workers[.]dev) that forwarded payloads to TeamPCP-controlled infrastructure on bulletproof hosting.

Attribution to TeamPCP (also tracked as PoisonedCodeProvider, PCP-Cluster) is HIGH confidence. The packer, control-flow flattening pattern, AES-GCM key wrapping format, and Cloudflare Worker C2 fronting are reused from the prior Checkmarx Toolkit poisoning (TL-2026-0298) and the lottiefiles compromise (TL-2026-0312). The maintainer account was protected by 2FA but an active session token captured during the Checkmarx breach was replayed against npm's session API, which does not invalidate sessions on credential rotation. Bitwarden has issued advisories, rotated maintainer credentials, enabled npm provenance enforcement, and published file hashes for IR teams. CISA added the campaign to its supply chain compromise watch list on 2026-04-25.

MITRE ATT&CK techniques used in TL-2026-0425

Collection

T1005 Data from Local System; T1119 Automated Collection

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Command and Control

T1071 Application Layer Protocol; T1102 Web Service; T1573 Encrypted Channel

Initial Access

T1078 Valid Accounts; T1195 Supply Chain Compromise

Discovery

T1082 System Information Discovery; T1083 File and Directory Discovery; T1518 Software Discovery

Credential Access

T1539 Steal Web Session Cookie; T1552 Unsecured Credentials; T1555 Credentials from Password Stores

Persistence

T1554 Compromise Host Software Binary

Resource Development

T1583 Acquire Infrastructure; T1586 Compromise Accounts; T1608 Stage Capabilities

Impact

T1657 Financial Theft

Affected products and versions in Bitwarden CLI Hijacked in npm Supply Chain Attack Linked to

  • Bitwarden — @bitwarden/cli (npm)
    Vulnerable versions: 2026.4.7
    Fixed in: 2026.4.8; 2026.4.6
  • Bitwarden — Bitwarden CLI Docker Image
    Vulnerable versions: bitwarden/cli:2026.4.7; bitwarden/cli:latest pulled 2026-04-22 14:32 to 16:02 UTC
    Fixed in: bitwarden/cli:2026.4.8
  • Bitwarden — Bitwarden Server (session subsystem)
    Vulnerable versions: <= 2026.4.7
    Fixed in: 2026.4.8-hotfix1

Remediation for Bitwarden CLI Hijacked in npm Supply Chain Attack Linked to

Patches

  • Reinstall @bitwarden/cli from the canonical clean version 2026.4.8 or later (republished after takedown) with provenance verification enabled
  • Apply Bitwarden Server hotfix 2026.4.8-hotfix1 which invalidates all sessions created before 2026-04-23 and forces re-authentication

Immediate actions

  • Inventory all CI/CD systems, container images, and developer workstations that ran npm install or npm ci with @bitwarden/cli during the window 2026-04-22 14:30 UTC through 2026-04-22 16:10 UTC
  • Force-rotate all Bitwarden master passwords, vault encryption keys, and active sessions for any user whose workstation or build agent installed the malicious package
  • Rotate AWS access keys, GitHub PATs, NPM_TOKEN, CIRCLE_TOKEN, and any secrets present in environment variables on affected hosts
  • Block egress to telemetry-collector.bitwarden-cli-stats.workers.dev and the wider *.bitwarden-cli-stats.workers.dev namespace at perimeter and DNS resolver
  • Remove the trojanized package version from local npm caches, lockfiles, and Docker layer caches using npm cache clean --force and rebuild affected images

Workarounds

  • Pin to the last known-good version 2026.4.6 with a strict integrity hash until provenance verification is in place
  • Replace Bitwarden CLI with the official Bitwarden desktop bw export workflow on workstations until ecosystem trust is restored

Longer-term hardening

  • Enable npm package provenance verification (npm audit signatures) in all CI pipelines and reject unsigned or unverifiable installs
  • Pin @bitwarden/cli and other security-critical dev tooling to specific versions with integrity hashes in package-lock.json
  • Enforce hardware-backed FIDO2 2FA on all npm publisher accounts and disallow long-lived session tokens for write operations
  • Deploy SCA tooling that detects postinstall script anomalies and base64-encoded payloads in newly published versions
  • Segment CI/CD secrets so that build-time vault unlocks require ephemeral, scoped tokens rather than long-lived BW_SESSION environment variables

Weaknesses (CWE) in Bitwarden CLI Hijacked in npm Supply Chain Attack Linked to

CWE-506, CWE-829, CWE-522, CWE-798, CWE-552

Timeline of Bitwarden CLI Hijacked in npm Supply Chain Attack Linked to

  • Checkmarx breach disclosed; attacker exfiltrated SSO session cookies and OAuth refresh tokens for 240+ enterprise customers including third-party security tooling vendors.
  • TeamPCP begins replaying stolen Checkmarx-derived session tokens against downstream SaaS providers including npm, GitHub, and crates.io publisher consoles.
  • TeamPCP successfully replays an npm session token belonging to a Bitwarden release engineer; bypasses 2FA because npm session API does not require fresh re-authentication for publish.
  • Trojanized @bitwarden/cli version 2026.4.7 published to npm with embedded postinstall payload that exfiltrates credentials to telemetry-collector.bitwarden-cli-stats.workers.dev.
  • Phylum automated SCA pipeline flags the new version due to anomalous postinstall script size and base64 payload signature.
  • Bitwarden security team receives Phylum notification and internal anomaly alert; confirms unauthorized publish and contacts npm Trust & Safety.
  • npm Trust & Safety unpublishes the malicious version; package replaced with security-holding placeholder. Total exposure window: ~90 minutes; 11,402 downloads recorded.
  • Bitwarden publishes BWSA-2026-0009 advisory, releases server hotfix 2026.4.8-hotfix1 to invalidate all pre-incident sessions, and ships clean CLI release 2026.4.8.
  • SOCRadar publishes detailed analysis attributing the campaign to TeamPCP based on Cloudflare Worker C2 reuse, packer signature, and AES-GCM key wrapping format from prior Checkmarx Toolkit and lottiefiles compromises.
  • CISA publishes Alert AA26-115A documenting the cascading supply chain compromise from Checkmarx breach to Bitwarden CLI hijack and recommends immediate credential rotation for affected pipelines.
  • Threadlinqs Intelligence opens TL-2026-0425 for active monitoring; correlation against BeaconBeagle infrastructure data underway; victim notifications continue.
  • As of 2026-05-29, the specific trojanized @bitwarden/cli package was unpublished by npm within ~90 min, access revoked, and a clean version shipped (no end-user vaults accessed). But the actor TeamPCP (UNC6780/Mini Shai-Hulud) remains highly active, with new waves through May 17-19 (TanStack, Checkmarx Jenkins plugin, ~3,800 GitHub repos).

Sources cited for Bitwarden CLI Hijacked in npm Supply Chain Attack Linked to

Detection coverage for TL-2026-0425

As of 2026-04-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0425 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
20 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats