Bitwarden Official CLI Supply Chain Attack: 93 Minutes of GitHub Token Exposure Intensifies Risks for Crypto Enterprises
A backdoored version of Bitwarden's official CLI was distributed on npm for 93 minutes, stealing GitHub tokens, cloud credentials, and CI/CD secrets. The incident, linked to the Checkmarx campaign, mirrors the Bybit attack path, warning crypto firms about developer machine as new entry points.








