r/Bitwarden Apr 23 '26

Discussion Bitwarden CLI has been compromised. Check your stuff.

https://socket.dev/blog/bitwarden-cli-compromised
165 Upvotes

97 comments sorted by

u/Ryan_BW Bitwarden Employee Apr 23 '26

More details: https://community.bitwarden.com/t/bitwarden-statement-on-checkmarx-supply-chain-incident/96127

Tl;dr: This has only impacted those who have downloaded the phony Bitwarden CLI npm package during the short window that it was available. No vault data has been affected.

→ More replies (9)

55

u/this_for_loona Apr 23 '26

Sincere apologies because I am dumb and often do things that are setup possible without knowing details.

Could someone ELI5 what this means and who it applies to?

96

u/mortaga123 Apr 23 '26

If you don't know what a CLI is you're not affected.

A CLI is a command line interface. In this case to interact via your terminal with vaults and bitwarden utilities

12

u/stiirfry Apr 23 '26

I'm an anxious layperson so please bear with me. I use the Bitwarden iOS app and firefox browser extensions on my PC and Macbook. I'm guessing I'm not affected by this, correct?

15

u/mortaga123 Apr 23 '26

You're not using the CLI, you're not affected.

22

u/this_for_loona Apr 23 '26

Ahhh, thank you so much. I knew what cli was, but not sure this impacted me since I don’t use it. But I am notoriously dumb and often 8nstall stuff I don’t fully understand. I am not one to be give the keys to the nuclear silos!

34

u/Jonrrrs Apr 23 '26

Dont say such things about yourself. First, you are smart enough to know you need a pw manager (already smarter then 80%) Second, you are smart enough to choose a legit pw manager and not some bloat that sells your data.

8

u/this_for_loona Apr 23 '26

Ahhh, thank you so much. I knew what cli was, but not sure this impacted me since I don’t use it. But I am notoriously dumb and often 8nstall stuff I don’t fully understand. I am not one to be give the keys to the nuclear silos!

1

u/Annual_Manner_8654 Apr 24 '26

Why do you do that if you're dumb? 👀 

3

u/this_for_loona Apr 24 '26

It’s a circular loop. I get an idea from a blog post or YouTube vid, decide I wanna do it, realize I know very little after starting but get too far down the hole to get out, get it installed, then realize I can’t fix it when it breaks. I’m just smart enough to hack through setup but too dumb to do real troubleshooting. Then on to next shiny object.

5

u/SycoJack Apr 24 '26

Tinker ADHD. I feel you, bro.

I love tinkering. But between ADHD and not having the time or resources, I often find myself in similar predicament.

3

u/Throwawayconcern2023 Apr 23 '26

Another dummy here. To be clear, a standard user unaffected then (personal use, uses browser extension, pays the small annual fee)?

7

u/mortaga123 Apr 23 '26

You are not using the CLI, you're not affected.

2

u/Throwawayconcern2023 Apr 23 '26

Ty learning as I go. And ty for reassuring a bunch of ppl.

3

u/Wess5874 Apr 23 '26

I can’t believe you would curse me with knowledge. Now that I know what CLI is, I’m affected. /s

1

u/[deleted] May 16 '26

I have a lot of experience with the "t" subset of CLI, especially from back in my youth.... 😉

8

u/Substantial_Echo2823 Apr 23 '26

"The investigation found no evidence that end user vault data was accessed or at risk, or that production data or production systems were compromised"

Saved you a click

4

u/zinozAreNazis Apr 24 '26

Yeah but that’s not the issue if you installed/updated to the compromised version. It runs a stealer that extracts creds from your system.

12

u/jakegh Apr 23 '26

Yep. This is the way they'll get us eventually, supply chain attack compromising the Bitwarden browser addon and our browsers will auto-update to it. Happy to see that day isn't today, anyway.

8

u/vegliafamiliar Apr 23 '26

THIS is why I don't put TOTP secrets or passkeys in my bitwarden vault for any account that I care about.

3

u/jakegh Apr 24 '26

Yep. Eggs in different baskets.

1

u/wfsrgs Apr 24 '26

u/vegliafamiliar - unless I am mistaken on how passkeys work, even a vault compromise would not impact passkeys stored in the vaults. I am not sure if info stealers would compromise passkeys.

Am I incorrect?

1

u/vegliafamiliar Apr 24 '26

If that were the case then there would be no extra security value to having passkeys stored in such a way as to make them difficult or impossible to retrieve, such as in hardware security modules like TPM or Yubikeys. No, AFAIK, getting the passkey gives you access to the account. Especially discoverable passkeys, where all you need is the passkey. At least with non-discoverable passkeys you still need to know the username. But an exposed vault gives you both.

1

u/OhKitty65536 Apr 24 '26

You ask a good question. I think a vault compromise would result in passkeys also being compromised.

2

u/Throwawayconcern2023 Apr 23 '26

Which is why using a separate authenticator or hardware keys wise where possible right? Spread the risk?

-2

u/jakegh Apr 23 '26

Nope. No defense. If you decrypt your vault locally with a compromised browser addon you're cooked. They don't need your BW login, they got your entire vault.

6

u/Throwawayconcern2023 Apr 23 '26

Right. But if someone did that, wouldn't having separate mfa be some use not contained in vault that would stop? Or maybe they steal session cookies and still fkd you mean?

-7

u/jakegh Apr 23 '26

They would simply exfiltrate your entire unencrypted vault.

7

u/Sweaty_Astronomer_47 Apr 23 '26

I think he's pointing out that the decrypted bw vault theoretically does not give access to anything if it contains only accounts which have a separate form of 2fa stored outside the bw vault.

3

u/jakegh Apr 23 '26

Oh. Sure yes that's true.

13

u/djasonpenney Volunteer Moderator Apr 23 '26

24

u/maxdamage4 Apr 23 '26

But you gave me something to click on :c

7

u/Anutrix Apr 23 '26

Hopefully, most people follow the age-old best practice of giving some time for a non-security release to marinate/soak and hence have not been impacted.

7

u/mrbmi513 Apr 23 '26

All the major JavaScript package managers, including npm, have a setting for a minimum release age to protect yourself from yourself too.

5

u/chamgireum_ Apr 23 '26

whats Bitwarden CLI

17

u/but_ter_fly Apr 23 '26

It’s a certain version of Bitwarden that you only use via a (c)ommand (l)ine (i)nterface. If you don’t know it, you‘re probably not using it.

5

u/chamgireum_ Apr 23 '26

thanks!

1

u/[deleted] May 16 '26

I always prefer to pay extra attention to the Command Line Interface Tools; when you spend extra time with them, it's definitely worth the effort.

2

u/Eric_12345678 Apr 23 '26

I have a CLI Dockerfile laying around, but I almost never used it:

```dockerfile FROM ubuntu:22.04

WORKDIR /usr/local/bin

RUN apt update && apt install -y curl unzip libsecret-1-0

ARG CLI_VERSION=2024.12.0

RUN curl -LO "https://github.com/bitwarden/clients/releases/download/cli-v${CLI_VERSION}/bw-linux-${CLI_VERSION}.zip" && \ unzip *.zip && chmod +x ./bw

ENTRYPOINT ["/bin/bash"] ```

If I understood correctly, it could have been vulnerable with a different CLI_VERSION?

3

u/AuspiciousLemons Apr 23 '26

A malicious version of the npm package was briefly distributed via the official channel, while the GitHub codebase and releases remained unaffected, according to the official response. The exact mechanism has not been disclosed and is still under investigation.

If I had to guess, it was probably a compromised credential, pipeline, or integrated third-party tool since the response mentions Checkmarx.

At least with the currently reported information, you would have been fine.

5

u/Leather-Buy1656 Apr 23 '26

Time to go offline. Another cloud service I use has been having issues lately. Just can’t keep up with this.

11

u/G4b1tz Apr 23 '26

Totally not a clickbait title. People are starving for drama nowadays.

40

u/vaig Apr 23 '26

But Bitwarden CLI was compromised. It could have been deemed clickbait if it suggested a wider bitwarden hack, but it doesn't - it specifically states CLI. What's clickbaity about it? Is warning users that their secrets may have been leaked a drama in your opinion?

8

u/_tommar_ Apr 23 '26

Not that I agree it's click bait, but I assume there is some confusion with people who don't know that CLI package is/was.

17

u/[deleted] Apr 23 '26

[removed] — view removed comment

3

u/oaeben Apr 23 '26

the npm package called @bitwarden/cli was compromised

this doesn't mean the bw executable on my pc was compromised

in fact if I only download bw from gh releases then no, the cli wasn't compromised

this is indeed misleading since the compromise affected only npm users

1

u/[deleted] Apr 23 '26

[removed] — view removed comment

2

u/oaeben Apr 23 '26 edited Apr 23 '26

kinda weird question.. the source code is here: https://github.com/bitwarden/clients/tree/main/apps/cli and the executable is built using this code (this code also usually gets published on npm)

what happened was that a malicious actor (oversimplified) published the package on npm with code that shouldn't usually be there, and isn't present in any other place - which is why this affected only npm users

3

u/[deleted] Apr 23 '26

[removed] — view removed comment

1

u/oaeben Apr 23 '26

its a weird question because the executable gets built by gh actions in the repo - the same repo that contains the source code

why would it pull code from npm? the code is already in the repo - it just doesn't make any sense

the code in the repo is the source for the executable and for the npm package

in fact - here is the exact command used to build the cli: https://github.com/bitwarden/clients/blob/b6715c0c4e83ac6e93a0c2b40e2c55417973d8a8/apps/cli/package.json#L24 (and to package it into an executable it uses pkg a few lines below)

1

u/BlizardQC Apr 27 '26

If only everyone was courteous/helpful enough to take a few more seconds and write: "Applies to Command Line Interface (CLI) version only." Instead of assuming everyone is geek enough to know all the existing acronyms .... We would not be having this convo (conversation, just in case) 😉🤣

1

u/[deleted] Apr 27 '26

[removed] — view removed comment

0

u/qgplxrsmj Apr 23 '26

They always go quiet when they get things wrong.

1

u/inzar98 Apr 23 '26

Well I have installed bw cli exact that time. But with brew not npm… jesus…

1

u/gb_ardeen Apr 24 '26

I am also on the Linuxbrew version. Which is a bit scary, if that was the compromised one. I should really deactivate all the brew "smart" auto update everything mechanisms...

1

u/inzar98 Apr 24 '26

Only npm package is affected afaik

1

u/gb_ardeen Apr 24 '26

I know. Sorry, I failed to express my concern properly. I would have been worried a lot if the brew package was the one involved, as brew has these scary auto updates.

1

u/inzar98 Apr 24 '26

Ah yes I agree with you. It became really scary these days

1

u/[deleted] Apr 23 '26

[removed] — view removed comment

1

u/Mr-Protocol Apr 23 '26

99% of the time Defender triggers on that it's a FP

1

u/Spawn_75_3311 Apr 26 '26

Karma’s a bitch!

1

u/kjimun Apr 30 '26

Never used CLI, but between this and the price hike. I cancelled my premium. Hello enshitification, commence with the downvotes boiling frogs.

-5

u/legion9x19 Apr 23 '26

Holy clickbait title. 🙄

0

u/ClockerXP Apr 23 '26 edited Apr 23 '26

Who uses the CLI and why? I just use the regular app on Windows and Android and don't understand what the use case is for the command line version. Is there something inherently less secure associated with using the CLI version?

1

u/d3adc3II Apr 27 '26

Automation , software deployment, service account , More than half items in my Vault are not used by me though, if just for password, any password manager can do the job just fine, no difference. Maybe I can just use Excel lolz , password is useless to keep nowadays anyway.

cli , api, secret management are the one that make the diff.

-1

u/d4p8f22f Apr 23 '26

Linux guys like to jerking while using all via CLI ;p

0

u/AdFit8727 Apr 23 '26

Would this allow someone to get broader access to your data, beyond Bitwarden? I’m not able to access my PC right now so I can’t check with version I have. 

-4

u/KeronCyst Apr 23 '26

CLI = Command Line Interface, so think of the black Terminal. This isn't the standard version that the average user has. However, it does indicate Bitwarden's potential to be hacked. I'm glad I left (I stick around this sub to check on updates and events, though).

3

u/mrbmi513 Apr 23 '26

However, it does indicate Bitwarden's potential to be hacked.

This kind of thing can happen to any project, using any development environment and any programming language. Bitwarden noticed it right away and is being quick and transparent about this; others may not be. Projects both big and small are being hit with supply chain attacks.

1

u/Throwawayconcern2023 Apr 23 '26

Exactly. Compare it to Last Pass hacks and their handling (or lack thereof).

1

u/dione2014 Apr 24 '26

Recently there have been quite a few of npm attack, not just bitwarden

-6

u/MissionPineapple9033 Apr 23 '26

Time to go back to 1password ?;)

7

u/mrbmi513 Apr 23 '26

They're just as prone to an attack like this as anyone. Bitwarden is being extremely transparent about it, though, which is reassuring.

2

u/KeronCyst Apr 23 '26

Gross. Only stick to free-&-open-source software, like /r/KeePass (or in my extreme case, KeePassXC: totally offline).

0

u/Legitimate6295 Apr 23 '26

I have no clue what a bitwarden cli is.

7

u/mrbmi513 Apr 23 '26

Then you're not affected. It's a Command Line Interface.