lemmy.net.au
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
Fedpie@sopuli.xyz to Privacy@lemmy.ml ·
edit-2
22 hours ago

Bitwarden CLI was compromised as part of an ongoing Checkmarx-related supply chain attack

alternativeto.net

external-link
message-square
17
fedilink
49
external-link

Bitwarden CLI was compromised as part of an ongoing Checkmarx-related supply chain attack

alternativeto.net

Fedpie@sopuli.xyz to Privacy@lemmy.ml ·
edit-2
22 hours ago
message-square
17
fedilink
Just a moment...
alternativeto.net
external-link

Link to the bitwarden post https://community.bitwarden.com/t/bitwarden-statement-on-checkmarx-supply-chain-incident/96127

alert-triangle
You must log in or register to comment.
  • trevor (he/they)@lemmy.blahaj.zone
    link
    fedilink
    English
    arrow-up
    20
    ·
    1 day ago

    Checkmarx itself is associated with Israeli Occupation Forces, so it shouldn’t be used by anyone in the first place.

  • iByteABit@lemmy.ml
    link
    fedilink
    arrow-up
    8
    ·
    1 day ago

    Can npm just disable the post install script feature at this point jfc, or put a ton of hurdles to jump over in order to use it just to make sure that this is always 100% meant to be there

  • RiQuY@lemmy.zip
    link
    fedilink
    arrow-up
    5
    ·
    edit-2
    1 day ago

    Did you share a link to the source? When I click on it, it behaves like a picture.

    • Luminous5481 "War Crimes Luminous" [they/them]@anarchist.nexus
      link
      fedilink
      English
      arrow-up
      5
      ·
      1 day ago

      that’s because it is a picture. they didn’t link a source.

    • floofloof@lemmy.ca
      link
      fedilink
      arrow-up
      4
      ·
      edit-2
      1 day ago

      Same here, using the default web interface, but this bug seems to happen sometimes on Lemmy: half the people see a link and the other half just an image. OP probably did post a link.

    • Fedpie@sopuli.xyzOP
      link
      fedilink
      arrow-up
      2
      ·
      edit-2
      22 hours ago

      I posted a link and upload a picture. But it looks like it change the link to the link of the picture I have changed it now.

    • sem@piefed.blahaj.zone
      link
      fedilink
      English
      arrow-up
      3
      ·
      1 day ago

      Didn’t read it but: https://www.forbes.com/sites/daveywinder/2026/04/24/bitwarden-confirms-compromise-here-are-the-facts-for-10-million-users/

      • Deer Tito (She/Her)@lemmygrad.ml
        link
        fedilink
        arrow-up
        3
        ·
        1 day ago

        So it only affected users of the CLI (Command Line Interface) for a short period of time, which means the vast majority of users are still safe.

        according to a moderator of the Bitwarden community forum, “it seems that only 334 Bitwarden users downloaded the malicious version of the CLI,” during the time it was available.

        • quack@lemmy.zip
          link
          fedilink
          arrow-up
          3
          ·
          1 day ago

          Like most supply chain attacks, it’s targeting developers and other people who use tooling like this rather than Bob and Alice on the street.

  • RustyNova@lemmy.world
    link
    fedilink
    arrow-up
    5
    arrow-down
    2
    ·
    1 day ago

    Damn.

    I’ll stick with my keepass + syncthing combo

    • superglue@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      15
      ·
      1 day ago

      This was a supply chain attack, everything is vulnerable to this type of attack.

    • atrielienz@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      edit-2
      1 day ago

      For a small window of time if you downloaded an update it had malware. It also looks like a lot of those downloads were bot downloads. There is no evidence that vaults have been compromised.

      In a post on X, JFrog said the rogue version of the package “steals GitHub/npm tokens, .ssh, .env, shell history, GitHub Actions and cloud secrets, then exfiltrates the data to private domains and as GitHub commits.”

      • RustyNova@lemmy.world
        link
        fedilink
        arrow-up
        1
        arrow-down
        2
        ·
        1 day ago

        Of what app? Keepass? Was from the Debian repos. Syncthing what’s from the syncthing repos

        • atrielienz@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          1 day ago

          Of Bitwarden.

          • RustyNova@lemmy.world
            link
            fedilink
            arrow-up
            1
            arrow-down
            5
            ·
            1 day ago

            I don’t use it. That’s the point.

            • quack@lemmy.zip
              link
              fedilink
              arrow-up
              10
              arrow-down
              2
              ·
              edit-2
              1 day ago

              That doesn’t make you safe from supply chain attacks generally. There’s no reason a supply chain attack couldn’t be applied to software repos you do use if a vulnerability exists within them and a bad actor is sufficiently motivated to exploit it.

              • RustyNova@lemmy.world
                link
                fedilink
                arrow-up
                1
                arrow-down
                3
                ·
                1 day ago

                Oh definitely. Not saying it’s impossible

                But here it would be arguably harder. Need to first get in the repos, and requires the user to log in to the password vault. Syncthing is easier to compromise, but good luck decrypting the vault

Privacy@lemmy.ml

privacy@lemmy.ml

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !privacy@lemmy.ml

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

  • Lemmy.ml libre_culture
  • Lemmy.ml privatelife
  • Lemmy.ml DeGoogle
  • Lemmy.ca privacy

much thanks to @gary_host_laptop for the logo design :)

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 614 users / day
  • 743 users / week
  • 750 users / month
  • 753 users / 6 months
  • 1 local subscriber
  • 48.2K subscribers
  • 307 Posts
  • 247 Comments
  • Modlog
  • mods:
  • k_o_t@lemmy.ml
  • tmpod@lemmy.pt
  • Yayannick@lemmy.ml
  • ranok@sopuli.xyz
  • BE: 0.19.9
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org