Bitwarden is a tool tracked across 18 threat clusters and 35 intelligence report mentions on ThreatCluster. First observed November 26, 2025; most recent activity July 14, 2026.
On July 1, 2026, security firm SlowMist identified a fake trading bot on GitHub designed to spread malware targeting Polymarket users and DeFi developers. The bot, named 'polymarket-arbitrage-bot', was promoted as a…
In 2026, significant cybersecurity incidents have emerged, including a data breach at the US Social Security Administration (SSA) linked to the Department of Government Efficiency (DOGE) led by Elon Musk. Reports…
In 2026, cyberattacks have escalated from data theft to targeting critical infrastructure, affecting government systems, educational platforms, and medical technology companies. The U.S. Department of Government…
The TeamPCP threat group has expanded its supply chain attack campaign, compromising the Microsoft DurableTask Python client with versions v1.4.1, v1.4.2, and v1.4.3 found to contain a credential-stealing worm. This…
A malicious version of the Bitwarden CLI password manager was distributed via npm, affecting version 2026.4.0 for a brief window on April 22, 2026. The attack exploited a compromised GitHub Action in Bitwarden's CI/CD…
Checkmarx, a software security firm, is investigating a significant data leak after its GitHub repository was compromised in a supply-chain attack on March 23, 2026. The attack, attributed to the TeamPCP cybercrime…
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
In late March 2026, the Vect ransomware group partnered with TeamPCP, a credential theft specialist, to enhance their cybercriminal operations. This collaboration aims to leverage TeamPCP's extensive credential…
GitGuardian has announced Developer Endpoint Protection to address the increasing risk of credential theft from developer laptops. Over the past year, supply chain attacks have targeted developer machines, leading to…
On May 20, 2026, GitHub confirmed a significant security breach involving a poisoned Visual Studio Code (VS Code) extension that compromised an employee's device. The attack, attributed to the TeamPCP hacking group,…