Civilloquy
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
versionc@lemmy.world to Selfhosted@lemmy.worldEnglish · 3 months ago

Bitwarden CLI distributed through NPM has been compromised. Bitwarden Statement on Checkmarx Supply Chain Incident.

community.bitwarden.com

external-link
message-square
89
fedilink
547
external-link

Bitwarden CLI distributed through NPM has been compromised. Bitwarden Statement on Checkmarx Supply Chain Incident.

community.bitwarden.com

versionc@lemmy.world to Selfhosted@lemmy.worldEnglish · 3 months ago
message-square
89
fedilink
Bitwarden Statement on Checkmarx Supply Chain Incident
community.bitwarden.com
external-link
The Bitwarden security team identified and contained a malicious package that was briefly distributed through the npm delivery path for @bitwarden/cli@2026.4.0 between 5:57 PM and 7:30 PM (ET) on April 22, 2026, in connection with a broader Checkmarx supply chain incident. Was I affected? If you use the Bitwarden command line interface and deploy using NPM, and downloaded the CLI between 5:57p ET and 7:30p ET on April 22, 2026, you may be affected. See remediation steps below. If you do not u...
  • captcha_incorrect@lemmy.world
    link
    fedilink
    English
    arrow-up
    35
    ·
    3 months ago

    What should be used instead?

    • grandma@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      22
      ·
      3 months ago

      Easy, just vendor all your dependencies! Can’t have a supply chain attack if you are the supply chain.

    • quick_snail@feddit.nl
      link
      fedilink
      English
      arrow-up
      7
      arrow-down
      1
      ·
      3 months ago

      A package manager that uses cryptographic signatures. Apt had this since 2005 iirc. Use apt.

      • AtHeartEngineer@lemmy.world
        link
        fedilink
        English
        arrow-up
        7
        ·
        3 months ago

        deleted by creator

        • quick_snail@feddit.nl
          link
          fedilink
          English
          arrow-up
          2
          ·
          3 months ago

          Packages are reviewed by package maintainers.

          Humans are required to solve a malicious insider. But most supply chain vulns of these shitty software dependency managers were resolved decades ago by freely available cryptography

          • AtHeartEngineer@lemmy.world
            link
            fedilink
            English
            arrow-up
            2
            ·
            3 months ago

            deleted by creator

      • captcha_incorrect@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        3 months ago

        Apt is great, but it does not work with every language. As an example, you cannot use apt with maven (java) AFAIK.

        • quick_snail@feddit.nl
          link
          fedilink
          English
          arrow-up
          1
          ·
          3 months ago

          Oh boy. Maven is like the only language dependency manager that does signing tho!

          You don’t need to use apt for java. Just use maven :)

          • captcha_incorrect@lemmy.world
            link
            fedilink
            English
            arrow-up
            2
            ·
            3 months ago

            Haha! Yeah, I don’t even know where to start if I wanted to use apt for this. I’ll stick with Maven for Java.

Selfhosted@lemmy.world

selfhosted@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !selfhosted@lemmy.world

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don’t control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don’t duplicate the full text of your blog or readme if you’re providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

  8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

Resources:

  • selfh.st Newsletter and index of selfhosted software and apps
  • awesome-selfhosted software
  • awesome-sysadmin resources
  • Self-Hosted Podcast from Jupiter Broadcasting

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 450 users / day
  • 2.13K users / week
  • 4.57K users / month
  • 12.2K users / 6 months
  • 1 local subscriber
  • 61K subscribers
  • 5.24K Posts
  • 83.5K Comments
  • Modlog
  • mods:
  • Ruud@lemmy.world
  • Loki@lemmy.world
  • CannaVet@lemmy.world
  • devve@lemmy.world
  • ayyy@sh.itjust.works
  • curbstickle_lw@lemmy.world
  • BE: 0.19.5
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org