# Bitwarden CLI Hijacked in npm Supply Chain Attack Linked to TeamPCP & Checkmarx Breach

> TeamPCP threat actors published a trojanized version of the @bitwarden/cli package to the npm registry on 2026-04-22, exposing CI/CD pipelines and developer workstations to credential vault exfiltration during a 90-minute window before takedown. The compromise leveraged maintainer credentials harvested from the prior Checkmarx breach and represents a cascading supply chain attack against credential management tooling.

- **Published:** 2026-04-27T12:00:00Z
- **Last reviewed:** 2026-04-27T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0425
- **ID:** TL-2026-0425
- **Severity:** CRITICAL (CVSS 9.6)
- **Category:** SUPPLY_CHAIN
- **Status:** MONITORING
- **Actor:** TeamPCP
- **Detections:** 9 · **IOCs:** 20 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On April 22, 2026, between approximately 14:32 UTC and 16:02 UTC, a malicious version of the @bitwarden/cli npm package (advertised as v2026.4.7) was published to the npm public registry by an account belonging to a legitimate Bitwarden release engineer whose credentials had been stolen during the March-April 2026 Checkmarx breach. The hijacked package was downloaded approximately 11,400 times across automated CI/CD pipelines, developer workstations, and container build images before npm Trust & Safety removed it following an internal anomaly alert and Bitwarden security team notification.

The trojanized package shipped with a benign-looking postinstall.js hook that decoded a Base64-encoded second-stage JavaScript payload at install time. The payload performed three primary actions: (1) it walked the local filesystem looking for Bitwarden vault export files (.json, .csv) under common paths; (2) it harvested high-value secret material from environment variables, .env files, ~/.aws/credentials, ~/.ssh/id_rsa, ~/.config/gh/hosts.yml, ~/.docker/config.json, and the GITHUB_TOKEN/NPM_TOKEN/CIRCLE_TOKEN family of CI variables; and (3) it called bw export with the BW_SESSION variable when present to extract live unlocked vaults. Stolen data was AES-256-GCM encrypted with an embedded public key, then exfiltrated over HTTPS to a Cloudflare Worker proxy (telemetry-collector[.]bitwarden-cli-stats[.]workers[.]dev) that forwarded payloads to TeamPCP-controlled infrastructure on bulletproof hosting.

Attribution to TeamPCP (also tracked as PoisonedCodeProvider, PCP-Cluster) is HIGH confidence. The packer, control-flow flattening pattern, AES-GCM key wrapping format, and Cloudflare Worker C2 fronting are reused from the prior Checkmarx Toolkit poisoning (TL-2026-0298) and the lottiefiles compromise (TL-2026-0312). The maintainer account was protected by 2FA but an active session token captured during the Checkmarx breach was replayed against npm's session API, which does not invalidate sessions on credential rotation. Bitwarden has issued advisories, rotated maintainer credentials, enabled npm provenance enforcement, and published file hashes for IR teams. CISA added the campaign to its supply chain compromise watch list on 2026-04-25.

## MITRE ATT&CK

- T1586 Compromise Accounts
- T1608 Stage Capabilities
- T1583 Acquire Infrastructure
- T1195 Supply Chain Compromise
- T1078 Valid Accounts
- T1059 Command and Scripting Interpreter
- T1204 User Execution
- T1554 Compromise Host Software Binary
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1036 Masquerading
- T1552 Unsecured Credentials
- T1555 Credentials from Password Stores
- T1539 Steal Web Session Cookie
- T1083 File and Directory Discovery
- T1518 Software Discovery
- T1082 System Information Discovery
- T1119 Automated Collection
- T1005 Data from Local System
- T1071 Application Layer Protocol
- T1573 Encrypted Channel
- T1102 Web Service
- T1041 Exfiltration Over C2 Channel
- T1567 Exfiltration Over Web Service
- T1657 Financial Theft

## Sources

- [Bitwarden CLI Hijacked in npm Supply Chain Attack Linked to TeamPCP & Checkmarx Breach](https://socradar.io/blog/bitwarden-cli-hijacked-npm-supply-chain-teampcp/)
- [Bitwarden Security Advisory BWSA-2026-0009: CLI npm Package Compromise](https://bitwarden.com/security/advisories/bwsa-2026-0009/)
- [CISA Alert AA26-115A: TeamPCP Cascading Supply Chain Compromise](https://www.cisa.gov/news-events/alerts/aa26-115a)
- [npm Trust & Safety Incident Report: @bitwarden/cli 2026.4.7 Removal](https://github.com/npm/security-holding/issues/2026-04-22-bitwarden-cli)
- [Reverse Engineering the TeamPCP Bitwarden CLI Payload](https://research.checkpoint.com/2026/teampcp-bitwarden-cli-reversing/)
- [Phylum Detection Write-up: bitwarden-cli@2026.4.7 Postinstall Hook](https://blog.phylum.io/bitwarden-cli-postinstall-2026-04-22/)
- [GitHub Security Lab: Indicators for TeamPCP Bitwarden Campaign](https://github.com/github/securitylab/advisories/teampcp-bitwarden-2026)
- [Bitwarden Customer Notification - April 2026 npm Incident](https://bitwarden.com/blog/april-2026-npm-incident/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0425
