lemmy.onlylans.io
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
versionc@lemmy.world to Selfhosted@lemmy.worldEnglish · 2 days ago

Bitwarden CLI distributed through NPM has been compromised. Bitwarden Statement on Checkmarx Supply Chain Incident.

community.bitwarden.com

external-link
message-square
117
fedilink
612
external-link

Bitwarden CLI distributed through NPM has been compromised. Bitwarden Statement on Checkmarx Supply Chain Incident.

community.bitwarden.com

versionc@lemmy.world to Selfhosted@lemmy.worldEnglish · 2 days ago
message-square
117
fedilink
Bitwarden Statement on Checkmarx Supply Chain Incident
community.bitwarden.com
external-link
The Bitwarden security team identified and contained a malicious package that was briefly distributed through the npm delivery path for @bitwarden/[email protected] between 5:57 PM and 7:30 PM (ET) on April 22, 2026, in connection with a broader Checkmarx supply chain incident. The investigation found no evidence that end user vault data was accessed or at risk, or that production data or production systems were compromised. Once the issue was detected, compromised access was revoked, the malicious ...
  • elgordino@fedia.io
    link
    fedilink
    arrow-up
    16
    arrow-down
    3
    ·
    2 days ago

    Everyone should be using minimumReleaseAge (or their package managers equivalent) to block installing recently updated packages.

    • SavvyWolf@pawb.social
      link
      fedilink
      English
      arrow-up
      11
      ·
      2 days ago

      Doesn’t that cause issues if a backdoor happened a few months ago and you should be updating to a recent fixed version?

      • Grass@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        5
        ·
        1 day ago

        we can never win. it’s simply not allowed

      • amorpheus@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 day ago

        Kind of, but if the backdoor is months old some hours don’t seem like they should matter.

      • anyhow2503@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 day ago

        It does. Enforcing a minimum package age can be useful for some applications, but the average user isn’t one of them.

    • KairuByte@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      6
      arrow-down
      1
      ·
      edit-2
      2 days ago

      Zero day goes brrrr

Selfhosted@lemmy.world

selfhosted@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don’t control.

Rules:

  1. Be civil: we’re here to support and learn from one another. Insults won’t be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it’s not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don’t duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

  7. No low-effort posts. This is subjective and will largely be determined by the community member reports.

Resources:

  • selfh.st Newsletter and index of selfhosted software and apps
  • awesome-selfhosted software
  • awesome-sysadmin resources
  • Self-Hosted Podcast from Jupiter Broadcasting

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 568 users / day
  • 2.27K users / week
  • 6.07K users / month
  • 15.8K users / 6 months
  • 2 local subscribers
  • 57K subscribers
  • 6.21K Posts
  • 152K Comments
  • Modlog
  • mods:
  • Ruud@lemmy.world
  • Loki@lemmy.world
  • CannaVet@lemmy.world
  • devve@lemmy.world
  • HybridSarcasm@lemmy.world
  • HybridSarcasm@lemmy.hybridsarcasm.xyz
  • BE: 0.19.8
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org