Is Shai-Hulud Back? Compromised Bitwarden CLI Contains a Self-Propagating npm Worm
aikido.dev | blog | #cloud | #supply-chain | #credential-theft | #npm | #ci-cd | #supply-chain-security | #worm | #shai-hulud | #bitwarden
Summary
A malicious @bitwarden/cli release carried a self-propagating worm self-named 'Shai-Hulud: The Third Coming', harvesting SSH keys, cloud secrets, and MCP configs via Bitwarden's compromised CI pipeline.
- Published
- Collected
Skip to content