Bitwarden CLI is a technology platform tracked by ThreatCluster, appearing in 7 threat clusters built from 9 intelligence report mentions.
Bitwarden CLI is a technology platform tracked across 7 threat clusters and 9 intelligence report mentions on ThreatCluster. First observed April 23, 2026; most recent activity July 2, 2026.
The TeamPCP threat group has expanded its supply chain attack campaign, compromising the Microsoft DurableTask Python client with versions v1.4.1, v1.4.2, and v1.4.3 found to contain a credential-stealing worm. This…
A malicious version of the Bitwarden CLI password manager was distributed via npm, affecting version 2026.4.0 for a brief window on April 22, 2026. The attack exploited a compromised GitHub Action in Bitwarden's CI/CD…
Checkmarx, a software security firm, is investigating a significant data leak after its GitHub repository was compromised in a supply-chain attack on March 23, 2026. The attack, attributed to the TeamPCP cybercrime…
xpl0itrs, a financially motivated threat actor group, has announced the launch of a data leak site on June 17, 2026, claiming access to over a dozen major companies. The group, known for its collaboration with TeamPCP,…
In late March 2026, the Vect ransomware group partnered with TeamPCP, a credential theft specialist, to enhance their cybercriminal operations. This collaboration aims to leverage TeamPCP's extensive credential…
TeamPCP, a financially motivated threat actor, has been conducting a campaign targeting software supply chains from March 19 to April 24, 2026. The group exploited trusted CI/CD and release workflows to steal sensitive…
On May 20, 2026, GitHub confirmed a significant security breach involving a poisoned Visual Studio Code (VS Code) extension that compromised an employee's device. The attack, attributed to the TeamPCP hacking group,…
Bitwarden CLI is a technology platform tracked by ThreatCluster, appearing in 7 threat clusters built from 9 intelligence report mentions.
The most recent intelligence report mentioning Bitwarden CLI on ThreatCluster is dated July 2, 2026. Activity was first observed April 23, 2026, giving a tracked span from then to July 2, 2026.
Across ThreatCluster reporting, Bitwarden CLI most frequently co-occurs with FAMOUS CHOLLIMA, Pressure Chollima, Stardust Chollima, TeamPCP, Data Breach, among 12 tracked related entities.
The most significant recent cluster is “TeamPCP Compromises Microsoft DurableTask and GitHub Actions in Supply Chain Attack” (11 articles · Updated May 20, 2026). Bitwarden CLI appears across 7 threat clusters in total, listed above with sources.
Bitwarden CLI appears in 9 intelligence report mentions across 7 deduplicated threat clusters, aggregated from 17,000+ monitored sources.