Tag Archives: npm security

Bitwarden CLI Compromise: Malicious npm Supply Chain Attack Discovered

A critical Bitwarden CLI compromise has been detected in the npm ecosystem, where attackers breached the CI/CD pipeline to inject credential-stealing code into version 2026.4.0. Continue reading

Posted in Security & Privacy, Threat Alerts | Tagged , , , | Leave a comment

Axios Supply Chain Compromise: CISA Issues Emergency Alert

CISA has issued an emergency alert regarding the Axios supply chain compromise, where malicious code in the popular NPM package delivers a Remote Access Trojan to developer environments and CI/CD pipelines. Continue reading

Posted in Security & Privacy, Threat Alerts | Tagged , , , | Leave a comment