IncidentBitwarden CLI Trojan: How a GitHub Action Became a Supply Chain Weapon
What Happened On April 22, 2025, attackers published a malicious version of the Bitwarden CLI password manager (version 2026.4.0) to the npm registry. The compromised package was available for about 1














