Lemmy
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
versionc@lemmy.worlddeleted by creator to Selfhosted@lemmy.worldEnglish · 2 months ago

Bitwarden CLI distributed through NPM has been compromised. Bitwarden Statement on Checkmarx Supply Chain Incident.

community.bitwarden.com

external-link
message-square
129
link
fedilink
652
external-link

Bitwarden CLI distributed through NPM has been compromised. Bitwarden Statement on Checkmarx Supply Chain Incident.

community.bitwarden.com

versionc@lemmy.worlddeleted by creator to Selfhosted@lemmy.worldEnglish · 2 months ago
message-square
129
link
fedilink
Bitwarden Statement on Checkmarx Supply Chain Incident
community.bitwarden.com
external-link
The Bitwarden security team identified and contained a malicious package that was briefly distributed through the npm delivery path for @bitwarden/cli@2026.4.0 between 5:57 PM and 7:30 PM (ET) on April 22, 2026, in connection with a broader Checkmarx supply chain incident. Was I affected? If you use the Bitwarden command line interface and deploy using NPM, and downloaded the CLI between 5:57p ET and 7:30p ET on April 22, 2026, you may be affected. See remediation steps below. If you do not u...
  • elgordino@fedia.io
    link
    fedilink
    arrow-up
    17
    arrow-down
    3
    ·
    2 months ago

    Everyone should be using minimumReleaseAge (or their package managers equivalent) to block installing recently updated packages.

    • SavvyWolf@pawb.social
      link
      fedilink
      English
      arrow-up
      13
      ·
      2 months ago

      Doesn’t that cause issues if a backdoor happened a few months ago and you should be updating to a recent fixed version?

      • Grass@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        6
        ·
        2 months ago

        we can never win. it’s simply not allowed

      • amorpheus@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        2 months ago

        Kind of, but if the backdoor is months old some hours don’t seem like they should matter.

      • anyhow2503@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 months ago

        It does. Enforcing a minimum package age can be useful for some applications, but the average user isn’t one of them.

    • KairuByte@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      8
      arrow-down
      1
      ·
      2 months ago

      Zero day goes brrrre

Selfhosted@lemmy.world

selfhosted@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !selfhosted@lemmy.world

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don’t control.

Rules:

  1. Be civil: we’re here to support and learn from one another. Insults won’t be tolerated. Flame wars are frowned upon.

  2. No spam.

  3. Posts here are to be centered around self-hosting. Please ensure it is clear in your post how it relates to self-hosting.

  4. Don’t duplicate the full text of your blog or git here. Just post the link for folks to click.

  5. Submission headline should match the article title.

  6. No trolling.

Resources:

  • selfh.st Newsletter and index of selfhosted software and apps
  • awesome-selfhosted software
  • awesome-sysadmin resources
  • Self-Hosted Podcast from Jupiter Broadcasting

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 802 users / day
  • 2.49K users / week
  • 7.16K users / month
  • 16.3K users / 6 months
  • 1 local subscriber
  • 60.1K subscribers
  • 3.61K Posts
  • 75.7K Comments
  • Modlog
  • mods:
  • Ruud@lemmy.world
  • Loki@lemmy.world
  • CannaVet@lemmy.world
  • devve@lemmy.world
  • ayyy@sh.itjust.works
  • curbstickle@anarchist.nexus
  • curbstickle_lw@lemmy.world
  • BE: 0.19.19
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org