[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3MBVgSy-NKTQsHi41HHGik0JWtSchpFBrhXXjn9WD0E":3},{"article":4,"iocs":51,"watch_terms":55},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":11,"published_at":13,"ingested_at":14,"relevance_score":15,"entities":16,"category_id":31,"category":32,"article_tags":35},"16935b2d-80d8-4a3d-a76b-29752591a613","‼️ Bitwarden Statement on Checkmarx Supply Chain Incident:\n\n\"The Bitwarden security team identifi...","bitwarden-statement-on-checkmarx-supply-chain-incident-the-bitwarden-security-te-d45c68","‼️ Bitwarden Statement on Checkmarx Supply Chain Incident:\n\n\"The Bitwarden security team identified and contained a malicious package that was briefly distributed through the npm delivery path for @bitwarden\u002Fcli@2026.4.0 between 5:57 PM and 7:30 PM (ET) on April 22, 2026, in","Bitwarden's security team detected and contained a malicious package injected into the @bitwarden\u002Fcli npm repository (version 2026.4.0) that was live for approximately 93 minutes on April 22, 2026. The incident appears linked to a Checkmarx supply chain compromise. Bitwarden has advised users to upgrade to patched versions and rotate any credentials that may have been exposed.","Bitwarden CLI malicious npm package distributed for 93 minutes on April 22, 2026.",null,"https:\u002F\u002Fx.com\u002FDarkWebInformer\u002Fstatus\u002F2047382490453614746","2026-04-23T18:29:58+00:00","2026-04-23T19:00:08.870747+00:00",9,[17,20,23,25,28],{"name":18,"type":19},"Bitwarden CLI","product",{"name":21,"type":22},"Bitwarden","vendor",{"name":24,"type":22},"Checkmarx",{"name":26,"type":27},"npm","technology",{"name":29,"type":30},"Checkmarx Supply Chain Incident","campaign","26b0b636-0e31-4db1-bffb-61bdf9f20a58",{"id":31,"icon":11,"name":33,"slug":34},"Supply Chain","supply-chain",[36,41,46],{"category":37},{"id":38,"icon":11,"name":39,"slug":40},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":42},{"id":43,"icon":11,"name":44,"slug":45},"ade75414-7914-4e23-a450-48b64546ee70","Open Source","open-source",{"category":47},{"id":48,"icon":11,"name":49,"slug":50},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[52],{"type":40,"value":53,"context":54},"@bitwarden\u002Fcli@2026.4.0","Malicious npm package version distributed via npm registry",[21,24,18]]