Bitwarden CLI 遭 Shai-Hulud 供应链攻击,定向窃取 Claude Code、Cursor、Codex CLI 的 API Key
Оригинальный заголовок: Bitwarden CLI 'Shai-Hulud' Supply Chain Attack Targeted Claude Code, Cursor, Codex CLI API Keys: 334 Developers Exposed
Заголовок и краткое изложение на выбранном языке ожидают перевода.
攻击者劫持 Bitwarden 的 CI/CD 流水线,向 npm 发布恶意 @bitwarden/[email protected],在 2026 年 4 月 22 日 5:57–7:30 PM ET 的 90 分钟窗口内被 334 名开发者安装。
复盘了恶意 npm 包如何定向窃取 AI 编程工具凭证,并给出 90 分钟窗口与影响范围等可核查细节。
Полный текст на выбранном языке ожидает перевода. Пока показан оригинал.
Bitwarden CLI 'Shai-Hulud' Supply Chain Attack Targeted Claude Code, Cursor, Codex CLI API Keys: 334 Developers Exposed
Attackers hijacked Bitwarden's CI/CD pipeline and published malicious @bitwarden/cli to npm. Malware explicitly scanned for Claude Code, Cursor, Codex CLI, and Aider API keys. 334 developers exposed in a 90-minute window on April 22, 2026.
Malicious @bitwarden/[email protected] published to npm after CI/CD pipeline hijack. Malware scanned .claude/, .cursor/, and Aider config paths for API keys, exfiltrating them via AES-256-GCM encryption to an attacker-controlled domain impersonating Checkmarx.
334 developers had AI API keys (Claude Code, Cursor, Codex CLI, Aider), GitHub tokens, and AWS/GCP credentials exfiltrated. Each compromised developer is a potential pivot point into every CI/CD pipeline and repository they can access.
2026-04-22
Attackers hijack Bitwarden's CI/CD pipeline and publish malicious @bitwarden/[email protected] to npm.
2026-04-22
Package available 5:57–7:30 PM ET (90-minute window). 334 developers install the malicious version.
2026-04-22
Malware scans .claude/, .cursor/, Aider configs; exfiltrates AI API keys, GitHub tokens, AWS/GCP credentials via AES-256-GCM.
2026-04-22
Bitwarden detects and removes malicious package. Clean version published.
2026-04-23
Palo Alto Networks, Endor Labs, and Sophos publish attribution to the Shai-Hulud campaign — linked to prior supply chain operations.
- The malware explicitly targeted .claude/, .cursor/, and Aider config directories — AI developer tool credentials are now a first-class supply chain target category.
- 90-minute availability window is consistent with organized supply chain actors: publish during off-hours, collect installs, remove before major detection systems fire.
- AES-256-GCM exfiltration to a Checkmarx-impersonating domain made initial triage harder — traffic blends with expected security tool callbacks.
- 334 exposed developers each represent a pivot into their downstream CI/CD pipelines — the blast radius is multiplicative, not linear.
- Shai-Hulud campaign linkage indicates an organized threat actor with experience specifically in npm supply chain operations.
Источник: Permission Protocol · AI Agent Incident Tracker · permissionprotocol.com