Bitwarden CLI compromised in the same attack chain as Checkmarx
Following up on the supply chain attack against Checkmarx, researchers at Socket found that Bitwarden's command line interface was also compromised. The incidents overlap in attack chain, payload capability and threat actor infrastructure. The Bitwarden payload additionally carries indicators not documented in the Checkmarx incident, including persistence through shell profiles. Shared tooling points strongly towards the same actor in both cases, though the researchers also observed differing operational signatures that complicate attribution.
What this means for your organisation
A command line tool for a password vault typically runs in automated processes, build jobs and on developer machines, which is precisely where secrets sit most densely. Persistence through shell profiles means the code runs again every time a terminal opens, even after the tool itself is removed. For management this is a concrete reminder that security tooling is not exempt from supply chain risk; if anything it is an especially attractive target.
Berigo recommends
- Determine where Bitwarden CLI runs in your environment, including build jobs and scripts nobody owns any more.
- Rotate secrets and access keys that may have been reachable by the tool during the affected period.
- Inspect shell profiles on affected machines for code that should not be there, and remove it.
- Write notification and incident handling obligations into your contracts with security vendors.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch