<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Bitwarden on HackingPassion.com : root@HackingPassion.com-[~]</title><link>https://hackingpassion.com/tags/bitwarden/</link><description>Recent content in Bitwarden on HackingPassion.com : root@HackingPassion.com-[~]</description><generator>Hugo</generator><language>en</language><lastBuildDate>Fri, 24 Apr 2026 11:30:31 +0200</lastBuildDate><atom:link href="https://hackingpassion.com/tags/bitwarden/index.xml" rel="self" type="application/rss+xml"/><item><title>Bitwarden CLI Backdoored on npm for 93 Minutes</title><link>https://hackingpassion.com/bitwarden-cli-supply-chain-attack/</link><pubDate>Fri, 24 Apr 2026 11:30:31 +0200</pubDate><guid>https://hackingpassion.com/bitwarden-cli-supply-chain-attack/</guid><description>&lt;p>Bitwarden&amp;rsquo;s CLI was backdoored and pushed to npm on April 22, 2026. It was live for &lt;strong>93 minutes&lt;/strong>. Every developer who installed it during that window has to treat their &lt;strong>entire machine as compromised&lt;/strong>. GitHub tokens, SSH keys, AWS credentials, cloud secrets. All of it.&lt;/p>
&lt;p>If you followed the Shai-Hulud story back in November 2025, this will sound familiar. That attack spread through npm and hit packages from Zapier, Postman, PostHog, and hundreds of others. &lt;strong>132 million monthly downloads affected.&lt;/strong> Stolen credentials dumped into public GitHub repositories for anyone to find. This new attack names itself &lt;strong>Shai-Hulud: The Third Coming&lt;/strong>, after the giant sandworms from Frank Herbert&amp;rsquo;s Dune. The irony is that this third wave specifically targets AI tools.&lt;/p></description></item></channel></rss>