GitGuardian analysis of the @bitwarden/cli compromise: GitHub used as C2, new Cloudflare exfiltration domain found, linked to April 22 Checkmarx KICS compromise via Dependabot.
First seen on securityboulevard.com
Jump to article: securityboulevard.com/2026/04/bitwarden-cli-gitguardian-views-on-helloworm00/
![]()

