Bitwarden Confirms Compromise—Here Are The Facts for 10 Million Users

TL;DR AI
2 min readKey summary
Bitwarden confirmed a malicious npm release briefly affected its CLI package on April 22, 2026.
The company says the incident was contained to the CLI distribution path and did not expose end-user vault data.
Only a small subset of CLI users appears to have been affected, limiting the overall impact.
The case highlights how supply-chain attacks can exploit trusted package channels like npm.



