Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

On April 22, 2026, threat actor TeamPCP published a malicious version of the @bitwarden/cli npm package (v2026.4.0) that remained publicly available for approximately 90 minutes before removal. Any developer or CI/CD pipeline that installed this version was exposed to exfiltration of npm authentication tokens, SSH keys, and cloud credentials for AWS, Azure, and Google Cloud Platform. A self-propagation mechanism means organizations that installed the package may have unknowingly poisoned downstream packages they control, extending blast radius well beyond direct victims.

Author

Tech Jacks Solutions