- Joined
- Aug 6, 2016
I looked into this without watching that faggot's video and found the statement released by Bitwarden.Fuck. What's this thread's preferred password manager these days?
tl;dr Bitwarden-CLI was affected by a supply chain attack where a Github Action in their CI/CD pipeline was compromised using stolen Github tokens, and a version of the bitwarden-cli package was published with a trojan in it. Checkmarx got hit with the same sort of attack, and both attacks tried to steal the same data from users: "GitHub and npm tokens, SSH keys, shell history, cloud credentials, and AI tool configurations for Claude, Cursor, and Aider." No other Bitwarden applications or user vault data were affected.


