Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign
1–10 of 458 posts
Re: Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign
#2Another day, another supply chain attack involving GitHub Actions.
Re: Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign
#3If I run the compromised CLI, do they get all my passwords?
Re: Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign
#4[deleted]
Re: Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign
#5This doesn't affect the web extension, no?
Re: Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign
#6Another day, another supply chain attack involving GitHub Actions.
GitHub was down too! Its uptime has been so bad recently.
Re: Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign
#7I had a really bad experience with the bitwarden cli. I believe it was `bw list` that I ran, assuming it would list the names of all my passwords, but too my surprise, it listed everything, including passwords and current totp codes. That's not the worst of it though. For some reason, when I ssh'ed into one of my servers and opened tmux, where I keep a weechat irc client running, I noticed that the entire content of the bw command was accessible from within the weechat text input field history. I have no idea how this happened, but it was quite terrifying. The issue persisted across tmux and weechat sessions, and only a reboot of the server would solve the problem.
I promptly removed the bw cli programme after that, and I definitely won't be installing it again.
I use ghostty if it matters.
Re: Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign
#8Another day, another supply chain attack involving GitHub Actions.
It’s the new Npm
Re: Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign
#9If I run the compromised CLI, do they get all my passwords?
Read the article
Re: Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign
#10If I run the compromised CLI, do they get all my passwords?
Exactly, that could widen the blast radius of this particular compromise significantly.